PcapXray Logo

PcapXray

0
Free
Visit Website

PcapXray is a network forensics tool designed to visualize a packet capture offline as a network diagram, highlighting important communication, device identification, and file extraction. The tool aims to speed up the investigation process by providing a detailed network diagram with features such as web traffic details, Tor traffic identification, possible malicious traffic, and data obtained from packets.

FEATURES

ALTERNATIVES

Tool for parsing Android logs events and protobuf data

A bash script for automating Linux swap analysis for post-exploitation or forensics purposes.

MFT and USN parser for direct extraction in filesystem timeline format with YARA rule support.

Dissect is a digital forensics & incident response framework that simplifies the analysis of forensic artefacts from various disk and file formats.

Python tool for remote memory acquisition

Visually inspect regex matches in binary data/text with YARA and regular expressions, displaying matched bytes and surrounding context.

Tool used for dumping memory from Android devices with root access requirement and forensic soundness considerations.

libevt is a library to access and parse Windows Event Log (EVT) files.