
TCPViewer
The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

The best-in-class macOS app to See every packet clearly on your Mac. Alternative to Wireshark

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Spip network sensor written in Go

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

This repository contains a list of new remediation scripts.

It was developed to speed up the processes of SOC Analysts during analysis

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

ngrep is like GNU grep applied to the network layer. It's a PCAP-based tool that allows you to specify an extended regular or hexadecimal expression…

Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.

A Zeek STUN protocol analyzer based on Spicy.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Wireshark RDP resources

This repository is for research purposes (2025 Sejong Univ. Capstone Design)

Dshell is a network forensic analysis framework.

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…