23 repository-uri
Tools for packet capture, traffic analysis, and network-level exploitation.
Explore 23 awesome GitHub repositories matching part of an awesome list · Network Security Analysis. Refine with filters or upvote what's useful.
Uptime Kuma is a self-hosted monitoring platform designed to track the availability and performance of network services and websites. It functions as a centralized dashboard that executes asynchronous health checks on a scheduled interval, providing real-time visibility into infrastructure health and service uptime. The platform distinguishes itself through a dedicated notification engine that dispatches alerts across multiple third-party messaging services, alongside a public status page generator that allows users to communicate service health and historical metrics via custom domains. Its
Self-hosted tool for monitoring service uptime.
This application is a desktop network traffic analyzer that provides real-time monitoring and forensic inspection of data packets. By interfacing directly with low-level system drivers, it captures raw network traffic from physical or virtual adapters to identify communication patterns, track bandwidth usage, and diagnose connectivity issues. The system distinguishes itself through an immediate-mode graphical interface that rebuilds the display state every frame, ensuring high responsiveness during live data updates. It maintains performance by using asynchronous message passing to decouple t
Application for monitoring local network traffic.
RustScan is a high-speed TCP network scanner written in Rust, designed for security reconnaissance and network mapping. It functions as an automated port discovery engine that identifies open ports on remote hosts using IPv6 addresses, CIDR ranges, or bulk input files. The tool is built for rapid surface area discovery, utilizing parallel port processing and OS-aware performance optimizations to identify active services. It allows for scan precision tuning through adjustable connection timeout thresholds and concurrent request controls to balance speed and accuracy. The system integrates wit
Fast port scanner designed for integration with Nmap.
Amass is a network attack surface mapper and reconnaissance framework designed to discover and map the external, internet-facing infrastructure of a target organization. It functions as an open source intelligence tool that identifies public network boundaries and locates hidden or forgotten subdomains to define an organization's total reachable footprint. The project utilizes passive-source data aggregation from external APIs and public databases alongside active DNS brute-forcing and recursive subdomain expansion. It employs a graph-based asset mapping system to visualize the relationships
Performs subdomain enumeration via scraping and brute forcing.
CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize
Automates post-exploitation tasks against network environments.
ntopng este un instrument de monitorizare a traficului de rețea bazat pe web și un agregator de date de flux. Acesta funcționează ca un monitor de securitate a rețelei, un sistem de gestionare a rețelei SNMP și un analizor de protocol industrial pentru medii OT și SCADA. Sistemul oferă inspecție specializată pentru protocoale industriale precum Modbus, DNP3 și IEC 60870. Se distinge prin detectarea comportamentală a amenințărilor, analiza traficului criptat prin amprentarea handshake-ului și capacitatea de a identifica hardware-ul și sistemele de operare folosind tipare DHCP și adrese MAC. Capabilitățile sale mai largi includ analiza traficului în timp real și capturarea pachetelor, maparea topologiei rețelei și orchestrarea ierarhiilor de colectare pe niveluri. Platforma gestionează, de asemenea, controlul accesului la rețea prin portaluri captive, impune cote de trafic și exportă datele de flux și alertă către baze de date externe precum ClickHouse, Elasticsearch și Kafka. Proiectul suportă executarea mai multor instanțe de monitorizare independente pe o singură gazdă folosind configurații izolate.
Detects security threats and anomalies through behavioral analysis, encrypted traffic inspection, and security tool integration.
Responder is a man-in-the-middle framework and network protocol spoofing tool designed to intercept network name queries and impersonate requested resources. It functions as a poisoner for LLMNR, NBT-NS, and MDNS, redirecting network traffic from clients to a controlled listener. The project serves as a credential capture tool that runs rogue servers for SMB, HTTP, and LDAP to collect NTLM hashes and clear text credentials. It enables the harvesting of encrypted authentication tokens and the interception of usernames and passwords sent without encryption. Its broader capabilities include int
Poisons network traffic to conduct man-in-the-middle attacks.
Rayhunter is an IMSI catcher detection tool and cellular network monitor designed to identify cell-site simulators and fake base stations. It functions as an SDR signal analyzer that tracks tower connectivity, logs GPS locations, and monitors for network downgrades or disabled encryption on mobile hardware. The system distinguishes itself through heuristic-based traffic analysis used to detect suspicious identity requests, malformed system information, and the use of null ciphers. It includes a remote device management interface consisting of a REST API and web dashboard for controlling detec
Processes captured traffic files using heuristics to identify potential IMSI catchers and simulators.
An engine to make Tor network your default gateway
Routes network traffic through the Tor network.
sslstrip is a MITM tool that implements Moxie Marlinspike's SSL stripping attacks.
Downgrades HTTPS connections to HTTP for traffic interception.
SSH man-in-the-middle tool
Intercepts and logs SSH/SFTP sessions and credentials.
A TCP/UDP Non-HTTP Proxy Extension for Burp Suite
Burp Suite extension for non-HTTP TCP/UDP proxying.
Secure multithreaded packet sniffer
Multithreaded packet sniffer focused on security.
DNSChef - DNS proxy for Penetration Testers and Malware Analysts
DNS proxy for manipulation and phishing attacks.
Hacking Toolkit
Python toolkit for performing network hacking tasks.
Title: TorCrawl.py Description: A Python script designed for anonymous web scraping via the Tor network. Author: MikeMeliz -->
Efficiently crawls .onion websites using Python.
A Linux packet crafting tool.
Linux-based tool for crafting network packets.
Discover internet-wide misconfigurations while drinking coffee
Discovers internet-wide misconfigurations using zgrab2.
PETEP (PEnetration TEsting Proxy) is an open-source Java application for traffic analysis & modification using TCP/UDP proxies. PETEP is a useful tool for performing penetration tests of applications with various application protocols. ⚡
Extensible proxy for TCP/UDP traffic analysis and modification.
Man in the Middle SOCKS Proxy for JAVA
Man-in-the-middle SOCKS proxy for Java environments.