
PiX-C2
Ping Exfiltration Command and Control (PiX-C2)

Ping Exfiltration Command and Control (PiX-C2)

A curated list of resources related to Industrial Control System (ICS) security.

Live, system-wide USB transfer sniffer in eBPF — decodes USB traffic inline (control SETUP, SCSI, HID) from two universal URB hooks. No usbmon, no…

DNSnitch is a local, privacy-first DNS server that puts you in complete control of your network traffic. Unlike passive blocklists, DNSnitch operates…

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

TP-Link WiFi SmartPlug Client and Wireshark Dissector

Prints the IPs on your local network that're sending the most packets

Deploys realistic virtual SCADA/ICS testbeds with IEC 60870-5-104 and OPC-UA nodes, enabling attack simulations, legitimate packet generation, and…

ICMP packet sniffer for capturing, analyzing, and logging Echo Request/Reply packets with filtering, SQLite storage, and PCAP export for network…

An open-source post-exploitation framework for students, researchers and developers.

Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures…

Snoopy v2.0 - modular digital terrestrial tracking framework

A python2 script for processing a PCAP file to decrypt C2 traffic sent to DOUBLEPULSAR implant

C# tool leveraging WinDivert driver to intercept and redirect Windows port 445 traffic for NTLM relay attacks via Cobalt Strike, enabling lateral…

Sinilink XY-WFTX Wifi Remote Thermostat Module Temperature Controller

Parsing Ramnit's traffic

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

Incident response walkthrough analyzing CVE-2023-46604 exploitation of Apache ActiveMQ via OpenWire, including PCAP analysis, IOC identification, and…