
zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Sniffs sensitive data from interface or pcap

This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP,…

TCP/IP packet demultiplexer. Download from:

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

This is a mini-firewall that completely isolates a target device from the local network.

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

KrbRoastParser is a tool for parsing Kerberos packets from pcap files to extract AS-REQ, AS-REP and TGS-REP hashes

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no…

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

This function combines all the above functions and takes necessary information from the user to change the IP and MAC address, start the responder…

CDPSnarf is a network sniffer exclusively written to extract information from CDP (Cisco Discovery Protocol) packets.

Lua plugin to extract data from Wireshark and convert it into MISP format

A tool to listen on a KNX bus via TPUART and the Calimero Project suite and to dump the data from the packets into a Wireshark-Compatible file hex…

My write-ups from CyberDefenders' Blue Team labs, solved using Wireshark. Covers TeamCity RCE (CVE-2024-27198), XSS session hijacking, and…

Selective protocol extractor from PCAPs or interfaces

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…