Utilities

Practical utilities for network evidence review.

Use focused tools to inspect authorized captures, normalize evidence, build timelines, and prepare investigation notes that can be validated by an analyst.

Live

Wireless PCAP Analyzer

Analyze authorized `.pcap`, `.pcapng`, and `.cap` files for WLAN artifacts, WPA/WPA3 posture, EAPOL activity, timelines, MAC inventory, and report outputs.

Open analyzer
In design

MAC and OUI Lookup

Normalize MAC formats, classify global/local/multicast addresses, and explain how much confidence an OUI lookup should carry.

Read related guides
In design

Wireshark Filter Builder

Generate filters for DNS, HTTP, TLS, EAPOL, beacons, probe responses, deauthentication, SMB, RDP, and suspicious conversations.

View filter notes
In design

Timeline Normalizer

Convert mixed timestamps into UTC case timelines and annotate source evidence for report writing.

View guide topics
In design

Hash and Evidence Note Builder

Create SHA256 records, capture summaries, acquisition notes, and case evidence checklists.

View methodology
Research

Network Scanners

Authorized assessment helpers keep active testing separate from forensic evidence handling and reporting.

Suggest a scanner
Evidence workflow

Analysis stays explainable.

Each utility preserves raw observations, shows the method used, and makes it easy to export evidence notes for independent review.