
IPED
IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…

IPED Digital Forensic Tool. It is an open source software that can be used to process and analyze digital evidence, often seized at crime scenes by…


All-in-One malware analysis tool.

PowerShell script that monitors Windows DNS traffic via pktmon to detect poisoning, spoofing, rogue resolver responses, and gateway MAC changes,…

RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Standalone Windows VM malware sandbox running capemon, with GUI triage viewer, YARA signatures, IOC extraction, network analysis, and…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

JA4+ is a suite of network fingerprinting standards

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

A network packet forensics tool for SSH

create cypher create statements for neo4j out of netstat files from multiple machines

Web-based Traffic and Cybersecurity Network Traffic Monitoring
