Repository navigation

#

network-forensics

PcapPlusPlus is a multiplatform C++ library for capturing, parsing and crafting of network packets. It is designed to be efficient, powerful and easy to use. It provides C++ wrappers for the most popular packet processing engines such as libpcap, Npcap, WinPcap, DPDK, AF_XDP and PF_RING.

C++
2976
17 小时前
Rust
1436
12 天前

Warning lists to inform users of MISP about potential false-positives or other information in indicators

Python
581
1 个月前

Poseidon is a python-based application that leverages software defined networks (SDN) to acquire and then feed network traffic to a number of machine learning techniques. The machine learning algorithms classify and predict the type of device.

Python
431
2 个月前

A course on "Digital Forensics" designed and offered in the Computer Science Department at Texas Tech University

Rich Text Format
193
2 年前

In progress. Web service for analyzing network traffic dumps (PCAP) with RAG. Detection of attacks through signature methods, integration with Threat Intelligence systems and AI.

Python
41
2 天前

A FUSE module to mount captured network data

C++
39
2 个月前

Network Forensic & Anomaly Detection System; tailored for covert channel/network steganography detection

Shell
27
1 年前

Some network covert channel projects of my own research, containing a protocol channel tool (protocol switching covert channel, PCT/PSCC), a protocol hopping covert channel (PHCC) tool, the protocol channel-aware active warden (PCAW) and ... VSTT.

C
16
5 个月前

The Network Traffic Analyzer is a Python script designed for capturing and analyzing network traffic, focusing primarily on DNS traffic. This tool provides users with the capability to monitor network activity in real-time and extract relevant information from captured packets.

HTML
8
1 年前

Overview of some network tools that can be used during the network forensics (extended with some publicly available datasets)

HTML
7
4 年前

The goal of this project is to help researchers/investigaters to export the decrypted TLS content into a PCAP

Python
7
1 年前

Program for static analysis of pcap files and recreation of information sent

Python
5
2 年前

Designing and implementing a Packet-Based Intelligent Network phishing Intrusion Detection system. The idea of the design is to use machine learning to classify Network packets to benign and phishing in real-time flow (for both http/https protocol) based on DNS records and domain name features. It operates by using a pre-programmed list of known phishing threat features and their indicators of compromise (IOCs). As a signature based INPDS it will monitor the packets traversing the network, it compares these packets to the database of known IOCs or attack signatures to flag any suspicious behavior.

Jupyter Notebook
4
3 年前

Usable web interface to perform offline network analysis

JavaScript
2
7 年前
Jupyter Notebook
2
1 年前