PaloAltoNetworks / tcpsession
A python library to extract TCP sessions from PCAPs.
☆22Updated 4 years ago
Alternatives and similar repositories for tcpsession:
Users that are interested in tcpsession are comparing it to the libraries listed below
- DHCP Fingerprinting☆28Updated 4 years ago
- A GUI/REST interface to find similarities in large sets (think: binaries). Based on ssdeep.☆19Updated 2 years ago
- DeepToad is a library and a tool to clusterize similar files using fuzzy hashing☆20Updated 4 years ago
- D-Scan project for office document analysis and generating flow diagram of macro in documents. For demo visit☆29Updated 3 months ago
- Script for pcap modification, reconstruction and anonymization☆18Updated 2 months ago
- Polyglot detector☆21Updated 10 months ago
- Using nDPI/openDPI to detect flow protocols from a PCAP file or live NIC. This program was modified from example in nDPI and I added a pe…☆23Updated 8 years ago
- Go implementation of the Community ID flow hashing standard☆20Updated last month
- Client library for the mwdb service by CERT Polska.☆40Updated 3 months ago
- Zeek package to generate a SMB client fingerprint☆27Updated 4 years ago
- Basic RDP honeypot script☆29Updated last year
- An Interactive Pcap Editor (based on Scapy)☆23Updated 4 years ago
- A simple python library to assist in working with cpes☆18Updated last year
- Ccollection of Linux loadable kernel modules aimed to logs any user action☆25Updated 5 years ago
- This python scripts can calculate the WHOIS Similarity Distance between two given domains.☆30Updated 2 years ago
- My Packet Captures, Quagga Tutorial, and Cisco Reversing.☆25Updated 6 years ago
- Passive DHCP fingerprinting implementation☆50Updated 8 years ago
- Pure python parser for Snort/Suricata rules.☆29Updated 11 months ago
- Extract TLS certificates from pcap files or network interfaces, fingerprint TLS client/server interactions with ja3/ja3s☆38Updated 5 years ago
- A proof of concept implementation of the Siemens S7 protocol analyser for the Bro IDS.☆16Updated 7 years ago
- ssdeep cluster analysis for malware files☆31Updated 4 years ago
- Application and service identification rules for Suricata☆18Updated 2 years ago
- Analytics for Accounting logs from Network devices☆17Updated 3 years ago
- The CRATOS proxy API integrates with your MISP instance and allows to extract indicators that can be consumed by security components such…☆13Updated 3 weeks ago
- D4 core software (server and sample sensor client)☆42Updated last year
- Growing collection of Spicy-based protocol and file analyzers for Zeek☆32Updated 5 months ago
- The Multiplatform Linux Sandbox☆15Updated last year
- ☆10Updated 9 years ago
- A set of YARA rules for the AIL framework to detect leak or information disclosure☆39Updated 3 weeks ago
- DIT is a DTLS MitM proxy implemented in Python 3. It can intercept, manipulate and suppress datagrams between two DTLS endpoints and supp…☆58Updated 3 years ago