Granef is a toolkit for network forensics that implements graph-based analysis of network traffic data. The toolkit processes network traffic captures and stores them in a Dgraph database for analysis through a web interface. Key components include: - Docker container modules for data processing - Transformation of Zeek logs from PCAP files into RDF triples - Support for MISP threat sharing data and NetFlow traffic analysis - Interactive web interface for exploratory data analysis - Database schema based on Zeek log format - Predefined queries and visualizations for network traffic analysis The system architecture consists of: - Extraction modules for processing input data - Transformation modules for data conversion - Data handling module with graph database - API module for querying - Web interface for analysis and visualization
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Scripts to automate the process of enumerating a Linux system through a Local File Inclusion (LFI) vulnerability.
Python tool for remotely or locally dumping RAM of a Linux client for digital forensics analysis.
An open source digital forensic tool for processing and analyzing digital evidence with high performance and multiplatform support.
Open Source computer forensics platform with modular design for easy automation and scripting.
LiME is a Linux Memory Extractor tool for acquiring volatile memory from Linux and Linux-based devices, including Android, with features like full memory captures and minimal process footprint.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.