a collection of useful wireshark/tshark plugins
-
Updated
Aug 19, 2020 - Lua
a collection of useful wireshark/tshark plugins
应急响应流量分析工具,支持pcap、excel、log等多种数据源,同时结合加解密、反编译等多个常用工作流。
🗝️ The Voidweaver's Trail: Season 1 Investigation Reports for Echo Response. Uncovering hidden identities and securing the Nullform Key across the Cyber Realm via advanced forensics and cryptanalysis.
ICS/OT cybersecurity scanner — Modbus, S7Comm & DNP3. Passive PCAP analysis + safe read-only Modbus scans. JSON/HTML reports + executive dashboards.
Forensic System: Professionelles Analyse-Tool für Computer- und Netzwerk-Forensik (DFIR). Bietet automatische Korrelation von Endpunkt-Prozessen und Netzwerk-Traffic, RAM-Analyse und gerichtsverwertbare Beweissicherung.
C2 Framework Fingerprinter: identifies Cobalt Strike, Metasploit, Sliver, Havoc, Covenant, Brute Ratel from PCAP traffic using beacon analysis, URI patterns, JA3, and HTTP headers
Analysis and Visualization of network traffic from data centres based on trace.pcap file.
Python network forensics tool that detects C2 beaconing, port scans, data exfiltration, DNS tunneling, and 20+ threat patterns in PCAP files. Behavioral analysis for the encrypted traffic era. Every finding maps to MITRE ATT&CK.
HTTP PCAP analysis using Wireshark, NetworkMiner and IP geolocation to investigate network traffic behaviour
AirSentinel is a Python-based cross-platform tool with a PyQt5 GUI for live Wi-Fi scanning and offline PCAP analysis. It detects network details, assigns risk levels, and exports results in JSON, Markdown, or PDF, making it valuable for cybersecurity research and testing.
A security-focused Python/Scapy platform for network visibility, behavioral detection, offline PCAP investigation, IOC extraction, and controlled response.
I do not know what I am doing yet! But it is my research!
AEGIS-Omega is a high-performance, hybrid multi-layer Intrusion Detection System (IDS). It features a 4-layer detection strategy—Signature Analysis, Autoencoder Anomaly Detection, BiLSTM Deep Learning, and Ensemble Fusion—to identify attack types with 95% F1-score. Includes a FastAPI backend, React dashboard, and PCAP,Netflow analysis.
GREP for PCAP files
Benchmark code and interactive results for autonomous network-attack detection by tool-using LLM agents investigating raw PCAPs.
Professional VoIP diagnostic tool - Analyzes PCAP files and detects one-way audio, NAT issues, call quality problems
Stratum is an open-source PCAP analyzer that turns network captures into flows, protocol events, correlated activity, and security findings through a compact web interface.
Network Traffic Analysis using Wireshark to detect Redline Stealer C2 communications. Includes PCAP analysis, IOCs, and incident report.
Scripts check the reputation of IP addresses and domain names present in your .pcap file using VirusTotal's free API. Provide an URL to your local LLM to prepare an automatic report. No data gets leaked to cloud LLM models.
Sniffing network traffic with Python for real-time or PCAP analysis.
To associate your repository with the pcap-analysis topic, visit your repo's landing page and select "manage topics."