
cve-2023-4966-iocs
Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation.

Python script to search Citrix NetScaler logs for possible CVE-2023-4966 exploitation.


CitrixBleed 2 NetScaler honeypot logs

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

ngrep is like GNU grep applied to the network layer. It's a PCAP-based tool that allows you to specify an extended regular or hexadecimal expression…

NTLMRawUnhide.py is a Python3 script designed to parse network packet capture files and extract NTLMv2 hashes in a crackable format. The following…

This project is now part of @mitmproxy.

ShadowNet is an anonymous routing protocol that forces all connections (system-wide) to go through Tor while implementing Mixnet-like…

It was developed to speed up the processes of SOC Analysts during analysis

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

Fingerprint SSH clients and servers.

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

OpenFPC, Open Source Full Packet Capture

Cisco IOS XE implant scanning & detection (CVE-2023-20198, CVE-2023-20273)

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.