01Analyzes PCAP/PCAPNG network traffic captures for security events
02Detects and classifies common port scanning techniques (SYN, FIN/NULL/Xmas, horizontal/vertical)
03Identifies suspicious IP addresses and extracts the first relevant scan event
04Enriches public IP addresses with threat intelligence (OTX, GreyNoise), ASN, and geolocation data
05Correlates multiple IP addresses to provide consolidated enrichment results
060 GitHub stars