GitHub topics: network-forensics
FoxIO-LLC/ja4
JA4+ is a suite of network fingerprinting standards
Language: Rust - Size: 14.9 MB - Last synced at: 1 day ago - Pushed at: 5 days ago - Stars: 1,279 - Forks: 114

seladb/PcapPlusPlus
PcapPlusPlus is a multiplatform C++ library for capturing, parsing and crafting of network packets. It is designed to be efficient, powerful and easy to use. It provides C++ wrappers for the most popular packet processing engines such as libpcap, Npcap, WinPcap, DPDK, AF_XDP and PF_RING.
Language: C++ - Size: 89.6 MB - Last synced at: 1 day ago - Pushed at: 1 day ago - Stars: 2,867 - Forks: 697

D14b0l1c/Analysis
Detection modules for 802.11 and Ethernet timing analysis using frame.time_epoch, clustering, and ML-based anomaly detection. Built for passive network behavior analysis.
Language: Python - Size: 7.53 MB - Last synced at: 2 days ago - Pushed at: 2 days ago - Stars: 0 - Forks: 0

harneferatsecurity/Certificados
Conquistas e Certificados
Size: 15.6 KB - Last synced at: 2 days ago - Pushed at: 2 days ago - Stars: 0 - Forks: 0

fkie-cad/friTap
Simplifying SSL/TLS traffic analysis for researchers by making SSL decryption effortless.
Language: JavaScript - Size: 31.3 MB - Last synced at: 4 days ago - Pushed at: 23 days ago - Stars: 343 - Forks: 32

MISP/misp-warninglists
Warning lists to inform users of MISP about potential false-positives or other information in indicators
Language: Python - Size: 362 MB - Last synced at: 7 days ago - Pushed at: about 1 month ago - Stars: 570 - Forks: 179

MichalSoltysikSOC/Cybersecurity-content-videos
Cybersecurity content (YouTube videos) | (1) How Web Protocol Weaknesses Enable Layer 7 DoS Attacks | (2) Deep packet inspection analyses - why the typical approach is not enough | (3) Deep Packet Inspection Analysis - Examining One Packet Killers | (4) Remcos RAT threat analysis on Windows including IEC 60870-5-104 traffic
Size: 27.1 MB - Last synced at: 12 days ago - Pushed at: 13 days ago - Stars: 1 - Forks: 0

MikeHorn-git/PsqlHunter
Hunt sql commands in pcap
Language: Python - Size: 2.74 MB - Last synced at: 7 days ago - Pushed at: 16 days ago - Stars: 2 - Forks: 0

gs-ai/DuskToDawn
DuskToDawn is a stealth-focused OSINT tool that gathers web intelligence anonymously using the Tor network and IP rotation.
Language: Python - Size: 1.74 MB - Last synced at: 29 days ago - Pushed at: 29 days ago - Stars: 2 - Forks: 0

N4rr34n6/Probe-Request-Capture-Tool
This PowerShell-based tool captures wireless network probe requests using TShark (the command-line version of Wireshark), processes the data in real time, and stores the results in a CSV file. The tool provides detailed insights into WLAN networks and associated MAC addresses, making it useful for network diagnostics and analysis.
Language: PowerShell - Size: 18.6 KB - Last synced at: about 1 month ago - Pushed at: about 1 month ago - Stars: 0 - Forks: 0

N4rr34n6/BitTorrent-Analysis-Tool
This PowerShell script (BitTorrent.ps1) processes a PCAPNG capture file to extract and analyze BitTorrent traffic.
Language: PowerShell - Size: 23.4 KB - Last synced at: about 1 month ago - Pushed at: about 1 month ago - Stars: 0 - Forks: 0

faucetsdn/poseidon
Poseidon is a python-based application that leverages software defined networks (SDN) to acquire and then feed network traffic to a number of machine learning techniques. The machine learning algorithms classify and predict the type of device.
Language: Python - Size: 20.1 MB - Last synced at: 8 days ago - Pushed at: about 2 months ago - Stars: 430 - Forks: 127

cdpxe/NetworkCovertChannels
Some network covert channel projects of my own research, containing a protocol channel tool (protocol switching covert channel, PCT/PSCC), a protocol hopping covert channel (PHCC) tool, the protocol channel-aware active warden (PCAW) and ... VSTT.
Language: C - Size: 394 KB - Last synced at: about 1 month ago - Pushed at: about 1 month ago - Stars: 16 - Forks: 5

medbenali/CyberScan
CyberScan: Network's Forensics ToolKit
Language: Python - Size: 16 MB - Last synced at: about 2 months ago - Pushed at: over 6 years ago - Stars: 444 - Forks: 131

stamparm/blackbook
Blackbook of malware domains
Size: 3.42 MB - Last synced at: about 2 months ago - Pushed at: 9 months ago - Stars: 240 - Forks: 39

asiamina/A-Course-on-Digital-Forensics
A course on "Digital Forensics" designed and offered in the Computer Science Department at Texas Tech University
Language: Rich Text Format - Size: 2.25 GB - Last synced at: 2 months ago - Pushed at: over 1 year ago - Stars: 178 - Forks: 45

fkie-cad/pcapFS
A FUSE module to mount captured network data
Language: C++ - Size: 218 MB - Last synced at: 9 days ago - Pushed at: 2 months ago - Stars: 37 - Forks: 6

MarwaRyan/Wireshark-Network-Traffic-Analyzer
Wireshark is a leading tool for network traffic analysis, widely used for education, research, and troubleshooting. 🌐🔍
Size: 1000 Bytes - Last synced at: 2 months ago - Pushed at: 2 months ago - Stars: 0 - Forks: 0

ichigonikefeed5966/Wireshark-Network-Traffic-Analyzer
Wireshark is a leading tool for network traffic analysis, widely used for education, research, and troubleshooting. 🌐🔍
Size: 6.84 KB - Last synced at: 3 months ago - Pushed at: 3 months ago - Stars: 0 - Forks: 0

fkie-cad/TLExport
The goal of this project is to help researchers/investigaters to export the decrypted TLS content into a PCAP
Language: Python - Size: 11.3 MB - Last synced at: 11 days ago - Pushed at: 9 months ago - Stars: 7 - Forks: 1

BraydenProckish/buffn3rd-Writeups
These are my writeups for cybersecurity platforms that will go in-depth on how I solved a challenge.
Size: 161 KB - Last synced at: 4 months ago - Pushed at: 4 months ago - Stars: 0 - Forks: 0

Baniur/Writeups
Write-ups for CTF-like, CyberSec training platforms (BTLO, CyberDefenders, Hack The Box Sherlocks)
Size: 11.7 KB - Last synced at: 7 months ago - Pushed at: 7 months ago - Stars: 1 - Forks: 0

johnbumgarner/forensics_tools
This repository contains various scripts that can be used to obtain information about IP addresses and MAC addresses.
Language: Python - Size: 28.3 KB - Last synced at: 10 months ago - Pushed at: 10 months ago - Stars: 0 - Forks: 0

Baniur/baniur.github.io
Write-ups for CTF-like, CyberSec training platforms (BTLO, CyberDefenders) | Repository of forensic artifacts which are useful in real world and CTF investigations
Size: 48.8 KB - Last synced at: 10 months ago - Pushed at: 10 months ago - Stars: 0 - Forks: 0

cdpxe/nefias
Network Forensic & Anomaly Detection System; tailored for covert channel/network steganography detection
Language: Shell - Size: 65.5 MB - Last synced at: about 1 month ago - Pushed at: about 1 year ago - Stars: 27 - Forks: 9

axmahr/PcapCleaner
Filter background traffic from capture files
Language: Python - Size: 40.8 MB - Last synced at: about 1 year ago - Pushed at: about 1 year ago - Stars: 0 - Forks: 0

lucadibello/wiremap-public
🛰️ A sophisticated network mapper and analyser
Size: 13 MB - Last synced at: 3 months ago - Pushed at: over 1 year ago - Stars: 0 - Forks: 0

farazulhoda/network-traffic-analysis
The Network Traffic Analyzer is a Python script designed for capturing and analyzing network traffic, focusing primarily on DNS traffic. This tool provides users with the capability to monitor network activity in real-time and extract relevant information from captured packets.
Language: Python - Size: 16.6 KB - Last synced at: about 1 year ago - Pushed at: about 1 year ago - Stars: 0 - Forks: 0

rhacrsse/AutomIoT
IoT Forensics Master Thesis @PoliMi
Language: Jupyter Notebook - Size: 73.5 MB - Last synced at: about 1 year ago - Pushed at: about 1 year ago - Stars: 2 - Forks: 0

IvanLetteri/MLfeaturesExtractor
Language: Python - Size: 57.7 MB - Last synced at: over 1 year ago - Pushed at: about 6 years ago - Stars: 0 - Forks: 0

abaker2010/bustaPcap
Program for static analysis of pcap files and recreation of information sent
Language: Python - Size: 73.2 KB - Last synced at: almost 2 years ago - Pushed at: almost 2 years ago - Stars: 5 - Forks: 0

nipunjaswal/networkforensics
Hands-On Network Forensics by Nipun Jaswal
Language: Python - Size: 53 MB - Last synced at: almost 2 years ago - Pushed at: almost 2 years ago - Stars: 33 - Forks: 20

ramirak/Packet-Detective
Sniff network traffic including passwords easily, with this packet sniffer for Linux.
Language: C - Size: 4.75 MB - Last synced at: about 2 years ago - Pushed at: about 2 years ago - Stars: 0 - Forks: 0

Khaoulahidaawi/NIPDS
Designing and implementing a Packet-Based Intelligent Network phishing Intrusion Detection system. The idea of the design is to use machine learning to classify Network packets to benign and phishing in real-time flow (for both http/https protocol) based on DNS records and domain name features. It operates by using a pre-programmed list of known phishing threat features and their indicators of compromise (IOCs). As a signature based INPDS it will monitor the packets traversing the network, it compares these packets to the database of known IOCs or attack signatures to flag any suspicious behavior.
Language: Jupyter Notebook - Size: 28.2 MB - Last synced at: about 2 years ago - Pushed at: almost 3 years ago - Stars: 1 - Forks: 0

MartinaZembjakova/Network-forensic-tools-taxonomy
Overview of some network tools that can be used during the network forensics (extended with some publicly available datasets)
Language: HTML - Size: 270 KB - Last synced at: about 2 years ago - Pushed at: about 4 years ago - Stars: 5 - Forks: 1

shivnshu/network-forensics-framework
Usable web interface to perform offline network analysis
Language: JavaScript - Size: 3.95 MB - Last synced at: about 2 years ago - Pushed at: almost 7 years ago - Stars: 2 - Forks: 0

githubfoam/tshark-githubactions
tshark network forensics ubuntu
Size: 14.6 KB - Last synced at: about 2 months ago - Pushed at: over 3 years ago - Stars: 0 - Forks: 0

githubfoam/tshark-sandbox
tshark network forensics ubuntu windows
Language: Shell - Size: 23.4 KB - Last synced at: about 2 months ago - Pushed at: over 3 years ago - Stars: 0 - Forks: 0

bolisettynihith/Intro-Network-Forensics-challenges
Contains beginner-level network forensics challenges from various CTFs.
Size: 11.8 MB - Last synced at: about 2 years ago - Pushed at: about 4 years ago - Stars: 0 - Forks: 0

githubfoam/moloch-sandbox
network security monitoring visibility , ELK, CTI, DFIR
Language: Shell - Size: 139 KB - Last synced at: about 2 months ago - Pushed at: almost 5 years ago - Stars: 0 - Forks: 0
