
GPEWebDefender
Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.


Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A terminal UI for tshark, inspired by Wireshark

Provides packet processing capabilities for Go

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

A Swiss army knife for your daily Linux network plumbing.

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

OpenFPC, Open Source Full Packet Capture

NetworkAssessment: Network Compromise Assessment Tool

Zeek support for Community ID flow hashing.

A flow-based network monitor with Deep Packet Inspection

A Zeek IPSec protocol analyzer based on Spicy.

A Zeek Wireguard protocol analyzer based on Spicy.

Bro analyzer that detects Google's QUIC protocol

A Zeek OSPF packet analyzer based on Spicy.

Selective protocol extractor from PCAPs or interfaces

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.