Search
Security · Wireshark
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 1.Dfir Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. | transilienceai/ | 563 | — | ~1.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 2 | This skill should be used when the user asks to "analyze network traffic with Wireshark", "capture packets for troubleshooting", "filter PCAP files", "follow TCP/UDP streams", "detect network… | zebbern/ | 4.7k | 8 repos | ~3k | Automated safety check: Pass | MIT | yesterday |
| 3 | 3.Iotnet IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications. | BrownFineSecurity/ | 859 | 1 repo | ~1k | Automated safety check: Notes | MIT | 4 mo ago |
| 4 | Guides authorized packet capture and analysis with TShark, Wireshark's command-line tool, for security investigations, malware detection and forensic examination of network traffic. | AgentSecOps/ | 220 | 1 repo | ~4.8k | Automated safety check: Notes | Unknown | 5 mo ago |
| 5 | Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic. | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 6 | Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. | wshobson/ | 40k | 8 repos | ~3.2k | Automated safety check: Pass | MIT | 6 days ago |
| 7 | A skill your agent uses for authorized reverse engineering of custom binary protocols, Protobuf/gRPC, WebSocket frames, and PCAP-driven protocol recovery. | zhaoxuya520/ | 41k | 2 repos | ~620 | Automated safety check: Warn | MIT | 19 days ago |
| 8 | 8.Net 嵌入式网络调试工具,用于发现接口、抓包、分析 pcap/pcapng、做连通性测试、端口扫描和流量统计. An agent skill from zhinkgit/embeddedskills. | zhinkgit/ | 734 | — | ~1.1k | Automated safety check: Pass | MIT | 1 mo ago |
| 9 | Perform forensic analysis of network packet captures (PCAP/PCAPNG) using Wireshark, tshark, and tcpdump to reconstruct network communications, extract transferred files, identify malicious traffic… | mukul975/ | 34k | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 10 | Detect Layer 2 ARP poisoning/spoofing by deploying ARPWatch, Dynamic ARP Inspection (DAI), Wireshark packet analysis, and custom Python monitoring scripts that flag gratuitous ARP floods, IP-to-MAC… | mukul975/ | 34k | — | ~3.8k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 11 | Capture and analyze network traffic using Wireshark and tshark to reconstruct network events from PCAP/PCAPNG files, extract transferred files and credentials, and identify command-and-control… | mukul975/ | 34k | — | ~3k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 12 | Deploy Zeek (formerly Bro) as a passive network security monitor to generate structured logs of protocol metadata (HTTP, DNS, TLS, SSH, SMTP, FTP, and more), write custom detection scripts, and… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 13 | Analyzes network traffic captures and flow data to identify adversary activity during security incidents, including command-and-control communications, lateral movement, data exfiltration, and… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Captures and analyzes network packet data using Wireshark and tshark to identify malicious traffic patterns, diagnose protocol issues, extract artifacts, and support incident response investigations… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Automate network traffic analysis using tshark (Wireshark CLI) and pyshark to compute protocol distribution statistics, detect suspicious flows such as port scans and beaconing, extract IOCs (IPs… | mukul975/ | 34k | — | ~610 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Analyzes network traffic generated by malware during sandbox execution or live incident response to identify C2 protocols, data exfiltration channels, payload downloads, and lateral movement… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | A skill your agent uses whenever the user asks about Wireshark, tcpdump, packet capture, pcap analysis, HTTP/DNS/TCP/DHCP/TLS capture interpretation, network lab reports, protocol fields observed in… | mingchen666/ | 244 | — | ~657 | Automated safety check: Pass | No licence | yesterday |
| 18 | Traffic analysis and PCAP forensics playbook. An agent skill from yaklang/hack-skills. | yaklang/ | 2.4k | — | ~2.8k | Automated safety check: Notes | MIT | 27 days ago |
| 19 | CTF 数字取证与信号分析技术。当挑战提供磁盘镜像(.dd/.E01)、内存 dump(.raw/.vmem)、网络抓包(.pcap/.pcapng)、隐写图片/音频、Windows 事件日志(.evtx)时使用。覆盖 Volatility 内存分析、Wireshark 流量还原、binwalk 隐写提取、文件系统恢复等取证全链路 | wgpsec/ | 1.8k | — | ~878 | Automated safety check: Notes | No licence | yesterday |
| 20 | Fast workflow to inspect PCAPs and extract protocol-level details using tshark | benchflow-ai/ | 1.8k | — | ~328 | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 21 | Analyze packet captures and network telemetry for intrusion evidence — capture and handling, the Wireshark/tshark triage funnel, Zeek log mining, Suricata rule runs, beacon and DNS-tunnel detection… | trilwu/ | 157 | — | ~5.3k | Automated safety check: Pass | MIT | 1 mo ago |
| 22 | CML packet capture — start, stop, download pcaps from CML lab links, integrate with Packet Buddy for analysis. | automateyournetwork/ | 676 | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 23 | Reverse engineer undocumented binary network protocols from packet captures and the client that speaks them — recovering framing and field structure, identifying length prefixes, opcodes, checksums… | trilwu/ | 157 | — | ~1.4k | Automated safety check: Pass | MIT | 1 mo ago |
| 24 | 24.Re Iot Proto 物联网协议:MQTT/CoAP/BLE/Zigbee;BLE 链路层(广播解析/配对加密)与 NFC/智能卡(ISO14443/APDU/MIFARE)。 | dslsdzc/ | 135 | — | ~3.2k | Automated safety check: Notes | Apache-2.0 | 6 days ago |
| 25 | 25.Soe This skill should be used when the user asks to "analyze security alerts", "parse vulnerability scan report", "analyze vulnerability scan report", "verify CVE fix", "analyze WAF attack log"… | infometa/ | 348 | — | ~2.3k | Automated safety check: Notes | No licence | yesterday |
| 26 | Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and root cause analysis. | mukul975/ | 301 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 27 | RouterOS packet capture and TZSP streaming for protocol debugging. | aiskillstore/ | 433 | — | ~2.6k | Automated safety check: Pass | No licence | yesterday |