Skip to content

Network Security

Capture, decode, and hunt across the wire.

Zeek

system

Protocol-aware network monitor that turns traffic into structured logs.

Suricata + ET Open rules

backports

IDS/IPS engine (installed from bookworm-backports — not in Debian's main archive) with the Emerging Threats Open ruleset pre-downloaded.

Wireshark / tshark / tcpdump

system

Packet capture and inspection, GUI and CLI.

Brim / Zui

app

Desktop app for searching Zeek logs and pcaps side by side.

Maltrail

venv

Detects known-malicious traffic against public blacklists/heuristics.