
packetStrider
Analyzes SSH packet captures using machine learning to predict reverse tunnels, keystrokes, data exfiltration, and authentication methods for…

Analyzes SSH packet captures using machine learning to predict reverse tunnels, keystrokes, data exfiltration, and authentication methods for…

All-in-one malware analysis tool for static and dynamic analysis of PE, ELF, Mach-O, APK, documents, scripts, archives, PCAP, and email files with…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

A tool to analyze the network flow during attack/defence Capture the Flag competitions

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Analyzes network traffic to detect C&C servers, peer-to-peer networks, and DNS fast-flux infrastructures, cross-referencing with known malware…

Endpoint visibility and collection tool using VQL queries for host-based state information gathering, incident response triage, and forensic artifact…

CLI tool to identify emails, IPs, URLs, cryptocurrency addresses, and API keys from text, files, or pcap data. Supports regex-based detection,…

Network forensic analysis tool for deep PCAP inspection, extracting passwords, authentication hashes, and network maps. Supports live capture,…

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

A tool for processing a lot of pcaps using tshark

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Forensic tool that maps Android network connections to their originating processes via ADB, without root, and enriches external IPs with geolocation,…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Captures raw 2G/3G/4G/5G cellular signaling from Qualcomm basebands via Diag, outputs PCAP for Wireshark, and exposes EFS/memory diagnostics.

This is the development tree. Production downloads are at:

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.