Dshell Logo

Dshell

0
Free
Visit Website

An extensible network forensic analysis framework that enables rapid development of plugins to support the dissection of network packet captures. Key features include deep packet analysis using specialized plugins, robust stream reassembly, IPv4 and IPv6 support, multiple user-selectable output formats, chainable plugins, parallel processing option, and the ability to create custom output handlers. It also provides guides such as the Dshell User Guide for installation and analysis, and the Dshell Developer Guide for plugin development. Requirements include Linux (developed on Ubuntu 20.04 LTS), Python 3 (developed with Python 3.8.10), pypacker, pcapy-ng, pyOpenSSL, and MaxMind GeoIP2 for geoip2.

FEATURES

ALTERNATIVES

Universal hexadecimal editor for computer forensics, data recovery, and IT security.

A reliable end-to-end DFIR solution for boosting cyber incident response and forensics capacity.

Anti-forensics tool for Red Teamers to erase footprints and test incident response capabilities.

A Kernel fuzzer focusing on race bugs

A command-line tool for creating hex dumps, converting between binary and human-readable representations, and patching binary files.

A library to access the Extensible Storage Engine (ESE) Database File (EDB) format used in various Windows applications.

No More Ransom is a collaborative project to combat ransomware attacks by providing decryption tools and prevention advice.

MalConfScan is a Volatility plugin for extracting configuration data of known malware and analyzing memory images.