
Malcolm
Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation…

Transparent man-in-the-middle proxy that terminates SSL/TLS connections, forges certificates on-the-fly, and logs decrypted traffic for network…

KeySweeper is a stealthy Arduino-based device, camouflaged as a functioning USB wall charger, that wirelessly and passively sniffs, decrypts, logs…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…


Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A terminal UI for tshark, inspired by Wireshark

Provides packet processing capabilities for Go

Wireshark's official code repository. You can keep the releases coming by donating at https://wiresharkfoundation.org/donate/.

TCP/IP packet demultiplexer. Download from:

A Swiss army knife for your daily Linux network plumbing.

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

A tool to analyze the network flow during attack/defence Capture the Flag competitions

'Packet Capture Forensic Evidence eXtractor' is a tool that finds and extracts files from packet capture files

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Pcap importer for Burp