
fastnetmon
Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Linux Bluetooth protocol stack with daemons, command-line clients, HCI monitor, and support for BR/EDR, LE, Mesh, audio profiles, providing device…

Advanced Network Interface Management and Monitoring

Full-lifecycle vulnerability management on a live Log4Shell (CVE-2021-44228) target — scan, manual exploitation, network detection, and remediation…

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

A terminal UI for tshark, inspired by Wireshark

Provides packet processing capabilities for Go

A Swiss army knife for your daily Linux network plumbing.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

This repository contains a list of new remediation scripts.

Pcap importer for Burp

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

An eBPF-powered Active Defense system that turns your Linux server into a deceptive honeypot. Features transparent traffic redirection, OS…

TheLightScope

Graph-first network traffic visualizer for live capture and PCAP replay with checkpoint diffing, path tracing, and Wireshark-style display filters…

Automation tool designed to simplify the analysis of PCAP (Packet Capture) files