Collaborative Network Forensics

What good is a large pcap if you can't mine the data, peek into it, search for terms and interactively explore conversations? We took a number of publicly available pcaps, indexed them and added a dash of Web 2.0 love. With over 22.8 GBytes and 54.9 million packets, this represents the largest collection of indexed pcaps online.

Network Forensics on such a large scale becomes a lonely, tiring endeavor. To cheer things up, we've added the ability for you to attach notes to packets and cross correlate interesting packets with other ones. You can also share cool searches with the rest of the community. This means you can flag packets with insightful (or not) comments about why you thought it was interesting. While you are at it, maybe you can find out who actually captured the flag?

Social nOtworking has never been this much fun!

Hack.Lu 2009

Captures from a honepot for the Information Security Visualization Contest. "For the 2009 conference, we make a contest to visualize data collected (network and tty captures) in a honeypot"

Capture the Flag event at Defcon17 published by the Diutinus Defense. "The DEFCON 17 CTF packet captures and binaries are now available via bittorrent."

Information Technology Operations Center

Captures from the 2009 Inter-Service Academy Cyber Defense Competition. "The annual competition pits the service academies, including West Point, against an actual National Security Agency Red Team. We release these data and log files in order to augment existing datasets to help develop better methods for detecting intrusions and attacks against our critical network infrastructure."

Update: If you are wondering why half of most conversations are missing, it's because of a misconfiguration during the capture.

Capture the Flag event at Defcon11 published by the Shmoo Group. "This archive contains data logged during the Capture the Flag Contest at DefCon. The Shmoo Group is publishing this data to promote the creation of more secure software and to offer data for research purposes."

If you know of other open repositories (with full packet contents), do let us know. We are happy to make them available to the community.