
irflow-timeline
DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt,…


Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A terminal UI for tshark, inspired by Wireshark

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

TCP/IP packet demultiplexer. Download from:

Malcom - Malware Communications Analyzer

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A tool to analyze the network flow during attack/defence Capture the Flag competitions

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Pcap importer for Burp

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

NetworkAssessment: Network Compromise Assessment Tool

OpenFPC, Open Source Full Packet Capture

Zeek support for Community ID flow hashing.

Lua plugin to extract data from Wireshark and convert it into MISP format