
IPBan
Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…

Automated IP ban service that detects failed login attempts from event logs and files, blocking attackers on Windows and Linux via firewall…

Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Open-source toolkit for reverse engineering, modeling, and fuzzing communication protocols. Infers message formats and state machines from network…

NTLMRawUnhide.py is a Python3 script designed to parse network packet capture files and extract NTLMv2 hashes in a crackable format. The following…

Transfer files to and from a Windows host via ICMP in restricted network environments.

KrbRoastParser is a tool for parsing Kerberos packets from pcap files to extract AS-REQ, AS-REP and TGS-REP hashes

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Network-based passive DNS logger capturing and logging DNS queries from live traffic or pcap files, outputting JSON for integration with SIEM and…

A python script to dump files and folders remotely from a Windows SMB share.

Open-source deception platform that turns any Linux machine into a high-signal canary. Deploy tripwire sensors on files, ports, and network services…

IP spoofing and SNMP community string brute-forcing tool to bypass ACLs on Cisco IOS devices, exfiltrate configuration files via TFTP.

Convert raw HTTP requests/responses into PCAP files for testing Snort IDS rules and network security analysis. Supports Docker deployment and…

A swiss-knife MCP server for analysing PCAP files

A Python script that gathers all valid IP addresses from all text files from a directory, and checks them against Whois database, TOR relays and…

Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

Rule-based linter for OpenSSH client config files that detects duplicate hosts, missing identity files, weak algorithms, wildcard ordering issues,…

Exfiltrate files using the HTTP protocol version ("HTTP/1.0" is a 0 and "HTTP/1.1" is a 1)