Feature extraction tool build in Rust using eBPF for network intrusion detection
-
Updated
May 16, 2024 - Rust
Feature extraction tool build in Rust using eBPF for network intrusion detection
Scapy: the Python-based interactive packet manipulation program & library.
NFStream: a Flexible Network Data Analysis Framework.
The default package source of the Zeek Package Manager. Wrote a package? See the README for how to get it included.
the LIBpcap interface to various kernel packet capture mechanism
Comfortably monitor your Internet traffic 🕵️♂️
Ingesting, pipelining, and enhancing your DNS logs with usage indicators, security analysis, and additional metadata.
Container terminal application for intercepting packets within pod/namespace using Scapy and ttyd terminal
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
Network traffic analysis tool for Attack & Defense CTF's
Arkime is an open source, large scale, full packet capturing, indexing, and database system.
Slips, a free software behavioral Python intrusion prevention system (IDS/IPS) that uses machine learning to detect malicious behaviors in the network traffic. Stratosphere Laboratory, AIC, FEL, CVUT in Prague.
A small set of tools to convert packets from capture files to hash files for use with Hashcat or John the Ripper.
Open source security data pipelines.
the TCPdump network dissector
🚀 A lightweight, fast, simple and complete solution for traffic analysis and intrusion detection.
PcapPlusPlus is a multiplatform C++ library for capturing, parsing and crafting of network packets. It is designed to be efficient, powerful and easy to use. It provides C++ wrappers for the most popular packet processing engines such as libpcap, Npcap, WinPcap, DPDK, AF_XDP and PF_RING.
Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)
Add a description, image, and links to the pcap topic page so that developers can more easily learn about it.
To associate your repository with the pcap topic, visit your repo's landing page and select "manage topics."