
joy
A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.
anomaly-detectiondigital-forensicsdns-analysis+7
1.4k

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Decodes PlugX traffic and encrypted/compressed artifacts

Decrypts Covenant C2 communications by extracting RSA private keys from minidumps, recovering AES session keys, and converting network captures to…

JA4+ is a suite of network fingerprinting standards

Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

Python wrapper for tshark, allowing python packet parsing using wireshark dissectors