
zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

USB device connection forensics tool that traces physical device-to-computer relationships across local and domain networks, generating visual graphs…

A network packet forensics tool for SSH

NetworkAssessment: Network Compromise Assessment Tool

ltm is a machine-history debugger for Linux. It records process, file, network, memory, and block-I/O metadata via eBPF, then lets you query the…

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it…

It was developed to speed up the processes of SOC Analysts during analysis


This is the development tree. Production downloads are at:

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

Extracts IP addresses from pcap/pcapng network traffic files and generates CSV reports with geolocation, ISP, and organizational details for each IP.

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

A swiss-knife MCP server for analysing PCAP files

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…