Skip to content

Entry

Maltrail

Appears in 5 awesome lists

A malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails and featuring an reporting and analysis interface.

Open github.comstamparm/maltrail

Found in these lists

Awesome Cybersecurity Blue Team

Section: Network Security Monitoring (NSM) · Malicious network traffic detection system.

StaleScore 53

Awesome Cybersecurity Blue Team - CN

Section: 网络安全监控(NSM) · 一个恶意网络流量检测系统

StaleScore 47

Awesome Malware Analysis

Section: Network · A malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails and featuring an reporting and analysis interface.

StaleScore 58

Security lists for SOC/DFIR detections

Section: General

FreshScore 84

awesome-python

Section: Security Tools · Malicious traffic detection system

FreshScore 81

Wireshark

Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education. Wireshark is very similar to tcpdump, but has a graphical front-end, plus some integrated sorting and filtering options.

In 20 listsDetails

mitmproxy

A Python tool used for intercepting, viewing and modifying network traffic. Invaluable in troubleshooting certain problems. (Source Code) MIT Python

In 10 listsDetails

Snort

Snort is a free and open source network intrusion prevention system (NIPS) and network intrusion detection system (NIDS)created by Martin Roesch in 1998. Snort is now developed by Sourcefire, of which Roesch is the founder and CTO. In 2009, Snort entered InfoWorld's Open Source Hall of Fame as one…

In 9 listsDetails

Zeek

(formerly Bro) is an open source software platform that provides compact, high-fidelity transaction logs, file content, and fully customized output to analysts, from the smallest home office to the largest, fastest research and commercial networks. From the FAQ: "Zeek provides a comprehensive…

In 6 listsDetails

tcpdump

A powerful command-line packet analyzer; and libpcap, a portable C/C++ library for network traffic capture

In 5 listsDetails

Stenographer

Packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. It stores as much history as it possible, managing disk usage, and deleting when disk limits are hit. It's ideal for capturing the traffic just before and during…

In 5 listsDetails

Fiddler

Free cross-platform web debugging proxy with user-friendly companion tools.

In 4 listsDetails

Tsunami

A general purpose network security scanner with an extensible plugin system for detecting high severity RCE-like vulnerabilities with high confidence. Custom detectors for finding vulnerabilities (e.g. open APIs) can be added.

In 3 lists