
arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Dshell is a network forensic analysis framework.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support


Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

ngrep is like GNU grep applied to the network layer. It's a PCAP-based tool that allows you to specify an extended regular or hexadecimal expression…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A tool to analyze the network flow during attack/defence Capture the Flag competitions

PA Toolkit is a collection of traffic analysis plugins focused on security

NTLMRawUnhide.py is a Python3 script designed to parse network packet capture files and extract NTLMv2 hashes in a crackable format. The following…

A network packet forensics tool for SSH

Wireshark RDP resources

eBPF-based toolkit for sniffing network traffic, extracting OpenSSL TLS keys, and intercepting/decrypting TLS 1.2 connections in real time using…

This project is now part of @mitmproxy.