How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.
Dshell is a network forensic analysis framework and traffic processor designed for the deep packet inspection of IPv4 and IPv6 traffic. It functions as an extensible forensic plugin system that captures, inspects, and analyzes network data to identify security anomalies and reconstruct communication streams. The system utilizes a plugin-based processing engine that allows for custom plugin development and plugin chaining. This modular architecture enables the creation of specialized analysis pipelines where network data is passed through a sequence of processing units for multi-step analysis.
Some set of scripts to unpack odin packets into separate files !!! Migrated to Codeberg !!!
Hadoop library to read packet capture (PCAP) files
The main features of ripe-ncc/hadoop-pcap are: Packet Analysis Tools, Security Data Analytics.
Projects with overlapping indexed features include: usarmyresearchlab/dshell — Dshell is a network forensic analysis framework and traffic processor designed for the deep packet inspection of IPv4… apache/incubator-spot — Mirror of Apache Spot. endgameinc/binarypig — Scalable Binary Data Extraction in Hadoop. kolanich/usbpcapodindumper — Some set of scripts to unpack odin packets into separate files !!! Migrated to Codeberg !!! apache/incubator-metron — Apache Metron. opensoc/opensoc — OpenSOC Apache Hadoop Code.