
joy
A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring.

Vulnerability detection scripts for the n8n product.

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

An event-driven network monitoring platform that performs live packet capture (Npcap), low-latency traffic analytics, and unsupervised threat…

Malcom - Malware Communications Analyzer

Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

Lua plugin to extract data from Wireshark and convert it into MISP format

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

Repo containing lua scripts and PCAP to find CVE-2020-0601 exploit attempts via network traffic

A network detection package for CVE-2020-16898 (Windows TCP/IP Remote Code Execution Vulnerability)