
BlueFish
Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

A network packet forensics tool for SSH

A tool to analyze the network flow during attack/defence Capture the Flag competitions

It was developed to speed up the processes of SOC Analysts during analysis

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

You didn't think I'd go and leave the blue team out, right?

Dshell is a network forensic analysis framework.

The Multiplatform Linux Sandbox

Decrypts Covenant C2 communications by extracting RSA private keys from minidumps, recovering AES session keys, and converting network captures to…

NetworkAssessment: Network Compromise Assessment Tool

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…