
bulk_extractor
This is the development tree. Production downloads are at:

This is the development tree. Production downloads are at:

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

This repository contains a full blue-team malware analysis of a real malicious DOCX exploiting CVE-2017-0199. The lab includes sandbox execution,…

You didn't think I'd go and leave the blue team out, right?

Provides packet processing capabilities for Go

Malware samples, analysis exercises and other interesting resources.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Pcap importer for Burp

It was developed to speed up the processes of SOC Analysts during analysis

Zeek support for Community ID flow hashing.

Android Connections Forensics

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.

Bro analyzer that detects Google's QUIC protocol

A Zeek OSPF packet analyzer based on Spicy.

A Zeek STUN protocol analyzer based on Spicy.

End-to-end simulation of a Python dependency confusion attack, sudo privilege escalation (CVE-2025-32463), and rootkit-based persistence - with full…