
PcapPlusPlus
Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

Corelight or Zeek Elastic Common Schema Templates

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit…

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Zero-Knowledge Credential Sharing

Chronicle parser for CORELIGHT and related information.

A Swiss army knife for your daily Linux network plumbing.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.

Provides packet processing capabilities for Go

Zeek support for Community ID flow hashing.

A terminal UI for tshark, inspired by Wireshark

A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further…

Backup Telegram chat logs with incremental support, multiple output formats (JSON, HTML, plaintext), and media download via telegram-cli remote…