Practical utilities for network evidence review.
Use focused tools to inspect authorized captures, normalize evidence, build timelines, and prepare investigation notes that can be validated by an analyst.
Wireless PCAP Analyzer
Analyze authorized `.pcap`, `.pcapng`, and `.cap` files for WLAN artifacts, WPA/WPA3 posture, EAPOL activity, timelines, MAC inventory, and report outputs.
Open analyzerMAC and OUI Lookup
Normalize MAC formats, classify global/local/multicast addresses, and explain how much confidence an OUI lookup should carry.
Read related guidesWireshark Filter Builder
Generate filters for DNS, HTTP, TLS, EAPOL, beacons, probe responses, deauthentication, SMB, RDP, and suspicious conversations.
View filter notesTimeline Normalizer
Convert mixed timestamps into UTC case timelines and annotate source evidence for report writing.
View guide topicsHash and Evidence Note Builder
Create SHA256 records, capture summaries, acquisition notes, and case evidence checklists.
View methodologyNetwork Scanners
Authorized assessment helpers keep active testing separate from forensic evidence handling and reporting.
Suggest a scannerAnalysis stays explainable.
Each utility preserves raw observations, shows the method used, and makes it easy to export evidence notes for independent review.