
arp-dns-attacks
ARP spoofing, HTTP redirection, DNS spoofing and DNS forging using pcap library

ARP spoofing, HTTP redirection, DNS spoofing and DNS forging using pcap library

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Practical black-box adversarial packet generation against encrypted traffic classification with minimal overhead and full packet recoverability.

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

Forensic triage of DNS cache poisoning in legacy hardware. Includes PCAP analysis of 839-byte unsolicited record injections, CVE-2025-40778 mapping,…

SigCorr is the first open-source tool to detect cross-protocol attack chains spanning SS7/MAP, Diameter S6a, and GTPv2-C through unified subscriber…

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

📡 A python program to create a fake AP and sniff data.

Kyanos is a networking analysis tool using eBPF. It can visualize the time packets spend in the kernel, capture requests/responses, makes…

Malicious HTTP traffic explorer

An automated Wireless RogueAP MITM attack framework.


C# version of NTLMRawUnHide

A DNS spoofer tool written in Python3.

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

Study on CVE-2020-13401 vulnerability of containers in dockers older than 19.03.11


Python wrapper for tshark, allowing python packet parsing using wireshark dissectors