
Dshell
Dshell is a network forensic analysis framework.

Dshell is a network forensic analysis framework.


Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Web-based Traffic and Cybersecurity Network Traffic Monitoring


'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

A flow-based network monitor with Deep Packet Inspection

Command-line packet analyzer for network monitoring and data acquisition, capturing and displaying network traffic for troubleshooting and security…

Command-line packet analyzer for network monitoring and data acquisition, capturing and displaying network traffic for troubleshooting and security…

Command-line packet analyzer for network monitoring and data acquisition, capturing and displaying network traffic for troubleshooting and security…

Collection of Python and Perl scripts for digital forensics, incident response, and network analysis, including hash signature tooling and packet…

TheLightScope

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

A wireshark plugin to instrument ETW

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Corelight@Home script