
NetScope
Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

This repository contains a list of new remediation scripts.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Wireshark RDP resources

Selective protocol extractor from PCAPs or interfaces

A Zeek STUN protocol analyzer based on Spicy.

This project is now part of @mitmproxy.

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…


ngrep is like GNU grep applied to the network layer. It's a PCAP-based tool that allows you to specify an extended regular or hexadecimal expression…

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

Spip network sensor written in Go

Pcap (capture file) Analysis Toolkit(v.1)

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…

Dshell is a network forensic analysis framework.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark