
Qu1cksc0pe
All-in-One malware analysis tool.

All-in-One malware analysis tool.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A network packet forensics tool for SSH

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files


JA4+ is a suite of network fingerprinting standards

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…


Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

create cypher create statements for neo4j out of netstat files from multiple machines