
Malcolm
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

66-tool MCP server for dark web intelligence — breach data, ransomware tracking, Tor .onion access, malware analysis, blockchain intel, exploit…

Backup Telegram chat logs with incremental support, multiple output formats (JSON, HTML, plaintext), and media download via telegram-cli remote…

A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further…

Terminal UI for browsing and replaying AWS WAF v2 logs from CloudWatch, S3, and the sampling API, with YAML filtering, auth detection, and…

Zero-Knowledge Credential Sharing

Corelight or Zeek Elastic Common Schema Templates

Chronicle parser for CORELIGHT and related information.

Lightweight web-attack monitor. One Go binary + SQLite. Not OSSEC, not a WAF.

Multiplatform C++ library for high-performance network packet capture, parsing, crafting, and analysis. Supports libpcap, DPDK, AF_XDP, PF_RING, and…

A terminal UI for tshark, inspired by Wireshark

Provides packet processing capabilities for Go

A Swiss army knife for your daily Linux network plumbing.

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

Zeek support for Community ID flow hashing.

Splunk app for integrating and analyzing Corelight network detection data, enabling real-time threat hunting and incident response.