

Python script to check Palo Alto firewalls for CVE-2024-3400 exploit attempts

Some files for red team/blue team investigations into CVE-2021-44228

Check to see if your Palo Alto firewall has been compromised by running script againt support bundle.



A MITM (monster-in-the-middle) detection tool. Used to build MALCOLM:

A low to medium interaction honeypot.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

A network sniffer that logs all DNS server replies for use in a passive DNS setup

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

NTLMRawUnhide.py is a Python3 script designed to parse network packet capture files and extract NTLMv2 hashes in a crackable format. The following…

Botnet command & control monitor

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

An ssh honeypot with the XZ backdoor. CVE-2024-3094

LLMNR/NBNS/mDNS Spoofing Detection Toolkit

OpenFPC, Open Source Full Packet Capture