
wireshark-forensics-plugin
Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Dshell is a network forensic analysis framework.

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.


Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

PA Toolkit is a collection of traffic analysis plugins focused on security

Wireshark RDP resources

eBPF-based toolkit for sniffing network traffic, extracting OpenSSL TLS keys, and intercepting/decrypting TLS 1.2 connections in real time using…

This repository is for research purposes (2025 Sejong Univ. Capstone Design)

ngrep is like GNU grep applied to the network layer. It's a PCAP-based tool that allows you to specify an extended regular or hexadecimal expression…

This repository contains a list of new remediation scripts.

A tool for processing a lot of pcaps using tshark

This project is now part of @mitmproxy.

It was developed to speed up the processes of SOC Analysts during analysis

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files

This framework combines a set of existing open source tools into an integrated package that automates the forensics investigation process. It is able…