Skip to content

Curated list of NetFlow, network telemetry, flow analysis, JA3/JARM fingerprinting, Zeek tooling, and packet investigation resources for threat hunting and cyber operations.

Notifications You must be signed in to change notification settings

BrewedIntel/netflow-telemetry-resources

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 

Repository files navigation

NetFlow & Network Telemetry Resources

A curated collection of tools, datasets, and references for NetFlow, IPFIX, network telemetry, JA3/JA4, JARM, Zeek, and packet-based investigation workflows.
Ideal for threat hunters, SOC analysts, researchers, and network defenders.


Table of Contents


NetFlow & IPFIX Collectors

nfdump & nfsen

https://github.com/phaag/nfdump
Classic NetFlow collection and analysis tools.

pmacct

http://www.pmacct.net
Flexible flow data collection, aggregation, and BGP correlation.

ElastiFlow

https://github.com/robcowart/elastiflow
Full-featured NetFlow/IPFIX collector with SIEM-scale dashboards.

FastNetMon

https://fastnetmon.com
DDoS detection using NetFlow, sFlow, and SPAN traffic.


Flow Analysis Tools

FlowPlotter

Simple visualizations of flow patterns over time.

SiLK (CERT/CMU)

https://tools.netsa.cert.org/silk
Enterprise-grade flow processing & analytics suite.


JA3 / JA4 / TLS Fingerprinting

JA3

https://github.com/salesforce/ja3
TLS client fingerprinting for malware and C2 clustering.

JA3S

Server-side TLS fingerprinting.

JA4 / JA4X

Updated fingerprinting for modern TLS protocols.


JARM Fingerprinting

JARM

https://github.com/salesforce/jarm
TLS handshake-based server fingerprinting to track infrastructure.


Packet Capture & PCAP Analysis

Wireshark

https://www.wireshark.org
Essential PCAP analysis toolkit.

tcpdump

CLI packet capture powerhouse.

Brim

https://www.brimdata.io
Search and visualize large PCAP datasets with Zeek logs.


Zeek / Bro Resources

Zeek

https://zeek.org
Network security monitoring and protocol analysis at scale.

Zeek Package Manager

https://packages.zeek.org
Community scripts and analyzers.


Open Datasets

MAWI Traffic Archive

http://mawi.wide.ad.jp
Long-term packet traces for research.

CAIDA

https://www.caida.org
Network topology, AS relationships, and traffic datasets.


BGP, ASN & Routing Context

RIPEstat

https://stat.ripe.net
IP, prefix, and routing visibility.

bgp.tools

https://bgp.tools
Live ASN and routing metadata.

RouteViews

http://www.routeviews.org
Global routing table snapshots.


Contributing

Pull requests and additional tooling recommendations welcome.

About

Curated list of NetFlow, network telemetry, flow analysis, JA3/JARM fingerprinting, Zeek tooling, and packet investigation resources for threat hunting and cyber operations.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published