
arkime
Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Per-process network monitoring for your terminal with deep packet inspection. Cross-platform, sandboxed.

Very fast DDoS sensor with sFlow/Netflow/IPFIX/SPAN support

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

An event-driven network monitoring platform that performs live packet capture (Npcap), low-latency traffic analytics, and unsupervised threat…

Offline browser extension providing defensive analysis and detection guidance for CVE-2026-20127, with packet visualization, IOC extraction, and…

❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight…

Vulnerability detection scripts for the n8n product.

Zeek package to detect CVE-2022-21907 HTTP exploit attempts by analyzing packet captures for malformed requests and triggering alerts.

A network detection package for CVE-2020-16898 (Windows TCP/IP Remote Code Execution Vulnerability)

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

Curated list of awesome projects and resources related to Rust and computer security

Lua plugin to extract data from Wireshark and convert it into MISP format

PCAPs and Suricata signatures for detecting OpenSSL CVE-2022-3602 exploitation attempts, including malicious client/server traffic and legitimate…

Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation

FATT /fingerprintAllTheThings - a pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…