
imaginaryC2
Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Malicious HTTP traffic explorer

FakeNet-NG - Next Generation Dynamic Network Analysis Tool

sniff HDMI DDC (I2C) traffic

ngrep is like GNU grep applied to the network layer. It's a PCAP-based tool that allows you to specify an extended regular or hexadecimal expression…

Kyanos is a networking analysis tool using eBPF. It can visualize the time packets spend in the kernel, capture requests/responses, makes…

QCSuper is a tool communicating with Qualcomm-based phones and modems, allowing to capture raw 2G/3G/4G radio frames, among other things.


A python2 script for processing a PCAP file to decrypt C2 traffic sent to DOUBLEPULSAR implant

JA4+ is a suite of network fingerprinting standards

TP-Link WiFi SmartPlug Client and Wireshark Dissector

Capturing, analysing and responding to cyber attacks

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

eBPF-based toolkit for sniffing network traffic, extracting OpenSSL TLS keys, and intercepting/decrypting TLS 1.2 connections in real time using…

Secure multithreaded packet sniffer

eBPF - extended Berkeley Packet Filter tooling

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…