
windows-malware-behavioral-analysis
Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Active Bluetooth BR/EDR Sniffer/Injector as cheap as any ESP32 board can get. Works with Scapy ;-)

Bro analyzer that detects Google's QUIC protocol

Automated man-in-the-middle attack tool.

Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap…

Parsing Ramnit's traffic

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Proof-of-concept exploit for CVE-2021-33959 demonstrating UDP reflection amplification attack against Plex Media Server via crafted M-SEARCH packets…

An Open-source LTE Downlink/Uplink Eavesdropper

ARP spoofing, HTTP redirection, DNS spoofing and DNS forging using pcap library

Kyanos is a networking analysis tool using eBPF. It can visualize the time packets spend in the kernel, capture requests/responses, makes…

No-root network monitor, firewall and PCAP dumper for Android

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

Zeek package that uses OpenSSL to detect CVE-2020-0601 exploit attempts

DHCP option injector

BinProxy is a proxy for arbitrary TCP connections. You can define custom message formats using the BinData gem.