
keepass-exfil-forensics
Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

Network forensics writeup + tooling for a TryHackMe DFIR challenge: reverses a hex→Base64→XOR exfiltration chain from PCAP traffic, then recovers a…

A cli tool to proxy and analyze TCP connections.


USB Army Knife – the ultimate close access tool for penetration testers and red teamers.

KeySweeper is a stealthy Arduino-based device, camouflaged as a functioning USB wall charger, that wirelessly and passively sniffs, decrypts, logs…

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

My Aircrack-ng contribution with Thomas d'Otreppe

Selective protocol extractor from PCAPs or interfaces

Solitude is a privacy analysis tool that enables anyone to conduct their own privacy investigations. Whether a curious novice or a more advanced…

UPnP Pentest Toolkit for Windows

Corelight@Home script

Zeek plugin generating Mercury NPF fingerprints for TCP, TLS/DTLS, QUIC, HTTP, SSH, OpenVPN, and STUN to support network security monitoring.

A simple, reliable and reasonably fast network capture analyzer.

A Zeek OpenVPN protocol analyzer, based on Spicy.

CDPSnarf is a network sniffer exclusively written to extract information from CDP (Cisco Discovery Protocol) packets.

Automated man-in-the-middle attack tool.