
arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Spip network sensor written in Go

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

This repository contains a list of new remediation scripts.

Incident response walkthrough analyzing CVE-2023-46604 exploitation of Apache ActiveMQ via OpenWire, including PCAP analysis, IOC identification, and…

It was developed to speed up the processes of SOC Analysts during analysis

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

ngrep is like GNU grep applied to the network layer. It's a PCAP-based tool that allows you to specify an extended regular or hexadecimal expression…

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

A Zeek STUN protocol analyzer based on Spicy.

Wireshark RDP resources

This repository is for research purposes (2025 Sejong Univ. Capstone Design)

Dshell is a network forensic analysis framework.