NetForensics is a high-performance, enterprise-grade Digital Forensics and Incident Response (DFIR) artifact extraction and threat inspection suite developed in Go (Golang). Built for Security Operations Center (SOC) analysts, incident responders, and forensic investigators, NetForensics enables passive real-time packet capture, deep offline .pcap / .pcapng parsing, bidirectional TCP stream reassembly, automated file carving, cryptographic integrity hashing (SHA-256 / MD5), multi-vector threat detection, and forensic timeline generation exportable to RFC 4180 CSV and structured JSON.
- Lead Systems & DFIR Engineer: Ahmad
- GitHub Profile: @cys-dexter
- Repository: https://github.com/cys-dexter/netforensics
- Dual Ingestion Engine: Supports live packet capture via
libpcap/afpacketacross network interfaces with hardware timestamps and promiscuous mode. - Offline Forensics: Resilient offline inspection supporting legacy
.pcapand modern.pcapngfiles with automatic header detection and pure-Go fallback. - Hardware-Accelerated Filtering: In-kernel Berkeley Packet Filter (BPF) offloading to capture only relevant forensic flows (e.g.
tcp port 80 or udp port 53).
- Stateful Stream Assembly: Bidirectional TCP connection tracking (4-tuple sequencing, overlapping segments, out-of-order packet reordering).
- HTTP Payload Carving: Unpacks HTTP requests and responses, decodes
Transfer-Encoding: chunked, resolvesContent-Disposition: attachment; filename="...", and extracts transferred payloads directly into./extracted_artifacts/. - FTP Data Extraction: Monitors FTP control channels (port 21) for
RETR,STOR,PASV, andPORTcommands, correlating incoming dynamic data streams with original file transfers. - Magic-Byte Sniffing: Identifies Windows PE Executables (
.exe,.dll), Linux Binaries (.elf), Documents (.pdf,.docx), Archives (.zip,.7z,.gz), Images (.png,.jpg), and Scripts (.sh).
- Dual-Stream Hashing: Simultaneously calculates cryptographic SHA-256 and MD5 hashes for every extracted artifact and payload in real-time.
- Chain of Custody: Establishes forensic integrity verification with non-repudiation ledgers and timeline evidence hashes.
-
DNS Tunneling & Data Exfiltration:
- Dynamic Shannon Entropy calculation ($-\sum P(x) \log_2 P(x)$) over subdomains.
- Flags queries exceeding baseline length (
$> 45$ characters) or displaying Base32, Hex, or Base64 C2 encoding patterns (e.g., Cobalt Strike, iodine, dnscat2).
-
ARP Poisoning & MITM Detection:
- Maintains stateful in-memory IP-to-MAC hardware bindings.
- Detects MAC flip-flop / cache poisoning attacks attempting to hijack default gateways.
- Flags unsolicited Gratuitous ARP broadcasts.
-
Stealth Port Scanning Fingerprinting:
- Flags RFC 793 evasion scans: Xmas Tree Scan (
FIN+PSH+URG), Null Scan (no flags set), and FIN Scan (FINwithoutACK). - Identifies Robert Graham Masscan fingerprint via static TCP window sizing (
Window: 1024). - Detects rapid horizontal and vertical TCP port sweeps across configurable sliding time windows.
- Flags RFC 793 evasion scans: Xmas Tree Scan (
- Chronological Audit Trail: Aggregates packet events, threat alerts, and carved artifacts into an immutable timeline.
- Structured Exporters: One-click export to formatted JSON or RFC 4180 CSV for ingestion into Splunk, Elastic SIEM, or forensic case files.
Built with rivo/tview and gdamore/tcell/v2, NetForensics provides a visual terminal console with real-time updates and keyboard navigation:
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β NetForensics v1.0.0 | DFIR Network Forensics & PCAP Artifact Collector | Ahmad β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Packets: 12,450 | Volume: 8.42 MB | Rate: 1,420 pkt/s | Carved: 7 | π΄ Threat Detected β
ββββββββββββββββββββββββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββββββββββ€
β [1] Live Packets Stream (Focus: '1') β [2] Forensic Threat Alerts (Focus: '2') β
β 13:00:00.100 192.168.1.100 -> 8.8.8.8 β π΄ THREAT | DNS Tunneling / Exfiltration β
β 13:00:00.600 192.168.1.1 -> 192.168.1 β π΄ THREAT | ARP Cache Poisoning / MITM β
β 13:00:01.000 10.0.0.99 -> 192.168.1 β π΄ THREAT | TCP Xmas Tree Scan (Nmap -sX) β
ββββββββββββββββββββββββββββββββββββββββββββΌββββββββββββββββββββββββββββββββββββββββββββββ€
β [3] Carved Artifacts & Hashes ('3'/'f') β [4] Evidence Timeline (Focus: '4') β
β π΄ beacon.exe (68 B) [SHA256: f820e5...] β 13:00:00.100 [THREAT] DNS Covert Channel β
β π’ manual.pdf (2.4 MB)[SHA256: a1b2c3...]β 13:00:00.600 [THREAT] ARP Gateway Claimed β
ββββββββββββββββββββββββββββββββββββββββββββ΄ββββββββββββββββββββββββββββββββββββββββββββββ€
β [Tab] Cycle Panes | [1-4] Select | [e] Export Timeline | [f] Artifacts | [q] Quit β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
| Key | Action |
|---|---|
Tab / Shift+Tab |
Cycle focus across tables |
1 |
Focus Live Packets Table |
2 |
Focus Forensic Threat Alerts Panel |
3 or f |
Focus Carved Artifacts Table / Open Inspector |
4 |
Focus Evidence Timeline Table |
Arrow Keys |
Scroll up/down through records in active pane |
e |
Open interactive Timeline Export dialog (JSON / CSV) |
? or F1 |
Show modal Help dialog and Keybindings Cheatsheet |
q or Ctrl+C |
Gracefully quit and finalize evidence logs |
Run NetForensics in automated scripts, Docker containers, or SOC ingestion pipelines using -headless:
./bin/netforensics -r capture.pcapng -headless -timeline evidence.json -o json -out-dir ./extracted_artifactsFollowing standard Go project standards:
NetForensics/
βββ cmd/
β βββ netforensics/
β βββ main.go # CLI flag parsing, banner, signal handling, mode routing
βββ pkg/
β βββ capture/
β β βββ capture.go # Live capture & offline reader engine, BPF filtering
β β βββ stats.go # Atomic performance metrics & packet statistics
β βββ reassembly/
β β βββ stream.go # TCP stream reassembly & connection tracker
β β βββ carver.go # MIME sniffing, signature detection, artifact hashing
β β βββ ftp.go # FTP control parsing & data transfer correlation
β βββ forensics/
β β βββ engine.go # Threat detection orchestrator & subscription broker
β β βββ models.go # Alert models, threat levels (π’, π‘, π΄)
β β βββ hasher.go # Dual-stream MD5 & SHA-256 cryptographic hashing
β β βββ dns_tunnel.go # Shannon entropy calculation & DNS covert channel detection
β β βββ arp_poison.go # Dynamic ARP inspection & MITM detection
β β βββ port_scan.go # SYN, FIN, NULL, XMAS, Masscan fingerprinting
β β βββ forensics_test.go # Unit tests for threat detection algorithms
β βββ protocols/
β β βββ parser.go # Layer 2-7 packet dissector & TLS SNI extractor
β β βββ types.go # Protocol models & severity levels
β β βββ dns.go # DNS parser & subdomain extraction
β β βββ arp.go # ARP parser & gratuitous broadcast detector
β β βββ http.go # HTTP request/response dissector & filename extraction
β β βββ protocols_test.go # Protocol decoder unit tests
β βββ reporter/
β β βββ timeline.go # Forensic timeline model, event sequencing & integrity hash
β β βββ export_json.go # Structured DFIR JSON exporter
β β βββ export_csv.go # RFC 4180 CSV exporter
β β βββ reporter_test.go # Timeline and export unit tests
β βββ ui/
β βββ tui.go # Main TUI controller & metrics refresher
β βββ views.go # Split table views (Packets, Alerts, Artifacts, Timeline)
β βββ keybindings.go # Key event captures & modal dialogs
βββ testdata/
β βββ generate_pcaps.go # Synthetic forensic PCAP generator
β βββ forensic_sample.pcap # Sample PCAP containing real-world attack scenarios
βββ bin/
β βββ netforensics # Compiled production binary
βββ extracted_artifacts/ # Destination for carved files and payloads
βββ go.mod # Go module definition
βββ go.sum # Dependency checksums
βββ README.md # Project documentation
- Operating System: Linux (Ubuntu/Debian, Fedora, Arch, CentOS) or macOS.
- Go Compiler: Go
1.22or later. - Libraries:
libpcapdevelopment headers.
# Ubuntu / Debian
sudo apt-get update && sudo apt-get install -y libpcap-dev build-essential
# Fedora / RHEL
sudo dnf install -y libpcap-devel gcc
# Arch Linux
sudo pacman -S libpcap# 1. Clone repository
git clone https://github.com/cys-dexter/netforensics.git
cd netforensics
# 2. Verify dependencies
go mod verify
# 3. Build optimized binary
mkdir -p bin
go build -ldflags="-s -w" -o bin/netforensics ./cmd/netforensicsgo test -v -race ./..../bin/netforensics -r suspicious_traffic.pcapsudo ./bin/netforensics -i eth0 -bpf "port 80 or port 53 or port 21"./bin/netforensics -r malware_c2.pcapng \
-headless \
-out-dir ./investigation_artifacts \
-timeline evidence_report.json \
-o json./bin/netforensics -r compromise.pcap \
-headless \
-timeline evidence_report.csv \
-o csv================================================================================
NETFORENSICS DFIR INVESTIGATION SUMMARY
================================================================================
Lead Investigator: Ahmad
GitHub Reference: https://github.com/cys-dexter
Session Duration: 1.42s
Packets Ingested: 23 (16 pkt/s)
Traffic Volume: 1,714 bytes
Carved Artifacts: 1 files (Saved to: ./extracted_artifacts)
Forensic Alerts: 20 detected
Timeline Events: 22 chronological records
Evidence Hash (SHA): edeca5e53cf27865a40dc4dfac25762c177f0b7f7e4e8fdc46c35367b0efd7fb
================================================================================
Distributed under the MIT License. See LICENSE for details.