An curated collection of awesome resources about networking in cybersecurity

Overview

Networking & Cybersecurity

Welcome to the world of Networking. An ongoing curated collection of awesome software, libraries, frameworks, talks & videos, best practices, learning tutorials and important practical resources about networking in cybersecurity. Thanks to all contributors, you're awesome and wouldn't be possible without you! Our goal is to build a categorized community-driven collection of very well-known resources.

Table of Contents

Network Foundations

  • Computer networking refers to connected computing devices (such as laptops, desktops, servers, smartphones, and tablets) and an ever-expanding array of IoT devices (such as cameras, door locks, doorbells, refrigerators, audio/visual systems, thermostats, and various sensors) that communicate with one another.

network

TCP/IP Protocols

Note: Links without description are official RFCs from the Internet Engineering Task Force (IETF).

dhcp

Dynamic Host Configuration Protocol, or DHCP, is used to provide quick and centralized management of IP addresses and other TCP/IP settings on your network. These are things like host IP address, subnet mask, DNS settings, default gateway address, and so on (I call these “IP configuration settings”). When you power on your computer, a DHCP server likely provides these IP configuration settings to you. Even if you don’t have a stand-alone DHCP server, your default gateway likely has its own DHCP server feature.

DHCP really makes network management a lot easier. DHCP eliminates the need for manually assigning IP addresses to our devices. DHCP port number for server is 67 and for the client is 68. It is a Client server protocol which uses UDP services

Courses

Tutorials

Books

Software and Tools

  • Wireshark - The most popular free and open source network protocol analyzer.
  • tcpdump - A powerful open source command-line packet analyzer.
  • Nmap - A free and open source software for network discovery and security auditing.
  • Zenmap - The official Nmap Security Scanner GUI.
  • GNS3 - A powerful free and open source network simulator.
  • Cisco Packet Tracer - Cross-platform network visual simulation tool designed by Cisco Systems.
  • pfSense - An open source firewall/router computer software distribution based on FreeBSD.
  • WinBox - Official MikroTik GUI software for administration of MikroTik RouterOS.
  • Online nslookup - An online DNS client to view and debug DNS configuration.
  • Online whois - An online whois record tool for getting information about domains.
  • OUI Lookup Tool - An online OUI lookup for searching vendors of MAC addresses.
  • Draw.io - An open source software for creating network diagrams and topologies.

Certifications

Miscellaneous

Network Design Resources

Network Implementation

Routing

  • Free Range Routing - IP routing protocol suite for Linux and Unix platforms which includes protocol daemons for BGP, IS-IS, LDP, OSPF, PIM, and RIP.
  • VyOS - Open source network operating system that can be installed on physical hardware or a virtual machine on your own server, or a cloud platform.

SD-WAN

Switching

  • snabb - Snabb (formerly "Snabb Switch") is a simple and fast packet networking toolkit.

VPN

  • PiVPN - Simplest OpenVPN setup and configuration, designed for Raspberry Pi.

Network Services

  • Pi-Hole - Network-wide ad blocking via your own Linux hardware.

Network Simulators and Traffic Generators

  • GNS3 - Network software emulator that allows the combination of virtual and real devices, used to simulate complex networks.
  • Mininet - Instant Virtual Network on your Laptop.
  • WANem - Wide Area Network Emulator.
  • Ostinato - Packet crafter, network traffic generator and analyzer with a friendly GUI.
  • SIPp - Free Open Source test tool / traffic generator for the SIP protocol.
  • StarTrinity SIP Tester™ - VoIP monitoring and testing tool, VoIP recorder.
  • Multi-Generator - Open source software that provides the ability to perform IP network performance tests and measurements using TCP and UDP/IP traffic.
  • Network-Conditions-Emulator - Artificially limit uplink and downlink bandwidth, delay and loss rate on selected interfaces.
  • snabb - Snabb (formerly "Snabb Switch") is a simple and fast packet networking toolkit.
  • vqfx10k-vagrant - Vagrant files to bring up Juniper virtual QFX instances
  • Packet Communication Investigator - import network traffic into a graphtool to analyse packet interactions between machines and network
  • SafePcap - GDPR and NISTIR 8053 Compliance for your Pcap files
  • Arkime - Arkime augments your current security infrastructure to store and index network traffic in standard PCAP format, providing fast, indexed access
  • pyNTM - a network traffic modeler written in python 3.

Network Operations

Network Change Management

  • Batfish - Network configuration analysis tool that can find bugs and guarantee the correctness of (planned or current) network configurations.
  • Oxidized - Network device configuration backup tool. It's a RANCID replacement.
  • Netshot - Network configuration and compliance management software.
  • Jazigo - Jazigo is a tool written in Go for retrieving configuration for multiple devices, similar to rancid, fetchconfig, oxidized, Sweet.
  • fetchconfig - fetchconfig is a Perl script for retrieving configuration of multiple devices
  • sweet - Network device configuration backups and change alerts for the 21st century - inspired by RANCID!
  • stockpiler - Stockpiler gathers network device configurations and stores them in a local Git repository.

Network Automation

  • Napalm - Vendor neutral, cross-platform open source project that provides a unified API to network devices.
  • netmiko - Multi-vendor library to simplify Paramiko SSH connections to network devices.
  • trigger - Robust network automation toolkit written in Python that was designed for interfacing with network devices.
  • Ansible - IT automation platform that makes your applications and systems easier to deploy by using SSH, with no agents to install on remote systems.
  • nornir - Pluggable multi-threaded framework with inventory management to help operate collections of devices
  • CNaaS-NMS - Campus Network-as-a-Service - Network Management System. Software to automate management of a campus network (LAN).
  • pyats - pyATS enable network engineers to perform stateful validation of their device operational status
  • itential.com - ow-Code Automation for Physical, Virtual, and Cloud Networks(commercial)
  • AWX - the upstream project for Tower, a commercial derivative of AWX.
  • Unimus Unimus makes Network Automation and Configuration Management easy (commercial)

Network Monitoring

  • perfSONAR - Network measurement toolkit designed to provide federated coverage of paths, and help to establish end-to-end usage expectations.
  • UDPing - Measure latency and packet loss across a link.
  • Vaping - vaping is a healthy alternative to smokeping!
  • veryflow - Continuous network verification system.
  • Forward Networks - Network Behavior Analysis (Commercial).
  • ToDD - Distributed, testing-on-demand system focused on testing network related conditions.
  • pmacct - Small set of multi-purpose passive network monitoring tools, including Netflow or IPFIX generation.
  • LibreNMS - Network monitoring system that supports automatic discovery, alerting, distributed polling and others.
  • Observium - Low-maintenance auto-discovering network monitoring platform.
  • Elastiflow - Netflow collector and reporting

Security Monitoring

  • cPacket - Performance monitoring solutions that deliver real-time analysis and coverage (Commercial).
  • Proxmox Mail Gateway - Open-source email security solution helping you to protect your mail server against all email threats the moment they emerge.
  • FastNetMon - DDoS detection tool (Open Source or Commercial).
  • PyREBox - Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU
  • Canary - Honeypot solution (commercial)
  • CanaryTokens - Free honeytoken
  • Malcolm - Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files) and Zeek logs.
  • Zeek - Zeek is an open source network security monitoring tool.
    • zeek2es - A Zeek log to Elastic/OpenSearch log converter.

Network Inventory

  • phpipam - Open-source web IP address management application (IPAM).
  • nsot - Network Source of Truth is an open source IPAM and network inventory database.
  • netbox - IP address management (IPAM) and data center infrastructure management (DCIM) tool.
  • ipfabric - Network Topology Mapping & Visualization (Commercial)
  • drawthe.net - Draws network diagrams dynamically from a text file describing the placement, layout and icons.

Networking Labs

Related resources

DevNet Tools

  • Celery - Asynchronous task queue/job queue based on distributed message passing. It is focused on real-time operation, but supports scheduling as well.
  • Ajenti - Manage a remote Linux box at any time using everyday tools like a web terminal, text editor, file manager and others.
  • ProxMox Virtualiation Platform - Open-source platform for enterprise virtualization that tightly integrates KVM hypervisor and LXC containers, software-defined storage and networking functionality on a single platform, and easily manages high availability clusters and disaster recovery tools with the built-in web management interface.
  • ops_tcpdump_handler - Chef Cookbook to test network connectivity
  • chromaterm - ChromaTerm is a Python module and script used for coloring the output to terminals
  • telnetmyip.com - Simple service that returns your source IP information in a json format
  • icanhaztraceroute.com - Simple service that returns a traceroute back to your source IP
  • Who is my ISP? - Simple service that shows the ISP of an IP
  • NsLookup.io - Simple service that shows all DNS records for a domain name
  • netshoot - a Docker + Kubernetes network trouble-shooting swiss-army container

DevNet Monitoring

  • netdata - Distributed real-time performance and health monitoring.
  • Grafana - Open source software for time series analytics.
  • monit -Small Open Source utility for managing and monitoring Unix systems. Monit conducts automatic maintnance and repair and can execute meaningful causal actions in error situations.
  • Prometheus - Open-source systems monitoring and alerting toolkit originally built at SoundCloud.
  • sensu - Monitor servers, services, application health, and business KPIs. Collect and analyze custom metrics. Get notified about failures before your users do. Give your business the competitive advantage it deserves. (Open Source or Commercial)
  • ELK Stack
    • Elasticsearch - Open Source, Distributed, RESTful Search Engine.
    • LogStash - Transport and process your logs, events, or other data.
    • Kibana - Analytics and search dashboard for Elasticsearch.
  • Graylog - Parse and enrich logs, wire data, and event data from any data source (Commercial, Free for less than 5GB/day).

DevNet Knowledgebase

  • ITGlue - IT focused documentation solution (Commercial).

DevNet Inventory

  • Snipe IT - Open Source Asset Management tool.

Knowledge Resources

License

MIT License & cc license

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 International License.

To the extent possible under law, Paul Veillard has waived all copyright and related or neighboring rights to this work.

^ back to top ^

Owner
Paul Veillard, P. Eng
Welcome to the most extensive collection of encyclopedic knowledge in the World of CyberSecurity®
Paul Veillard, P. Eng
wireguard-config-benchmark is a python script that benchmarks the download speeds for the connections defined in one or more wireguard config files

wireguard-config-benchmark is a python script that benchmarks the download speeds for the connections defined in one or more wireguard config files. If multiple configs are benchmarked it will output

Sal 12 May 07, 2022
This is a zeep based SOAP client wrapper for simple communication with the Bricknode SOAP API.

This is a zeep based SOAP client wrapper for simple communication with the Bricknode SOAP API.

Nord Fondkommission AB 2 Dec 15, 2021
Easy to use gRPC-web client in python

pyease-grpc Easy to use gRPC-web client in python Tutorial This package provides a requests like interface to make calls to gRPC-Web servers.

Sudipto Chandra 4 Dec 03, 2022
Proxlist - Retrieve proxy servers.

Finding and storing a list of proxies can be taxing - especially ones that are free and may not work only minutes from now. proxlist will validate the proxy and return a rotating random proxy to you

Justin Hammond 2 Mar 17, 2022
libsigrok stacked Protocol Decoder for TPM 2.0 transactions from an SPI bus. BitLocker Volume Master Key (VMK) are automatically extracted.

libsigrok stacked Protocol Decoder for TPM 2.0 transactions from an SPI bus. BitLocker Volume Master Key (VMK) are automatically extracted.

Jordan Ovrè 9 Dec 26, 2022
This script will make it easier to connect to any wireguard vpn config

wireguard-linux-python-script-vpn This script will make it easier to connect to any wireguard vpn config also u will need your wireguard vpn from your

Jimo 1 Sep 21, 2022
A simple GitHub Action that physically puts your senses on alert when your build/release fails

GH Release Paniker A simple GitHub Action that physically puts your senses on alert when your build/release fails Usage Requirements: Raspberry Pi, LE

Hemanth Krishna 5 Dec 20, 2021
Exfiltrate files using the HTTP protocol version ("HTTP/1.0" is a 0 and "HTTP/1.1" is a 1)

http-protocol-exfil Use the HTTP protocol version to send a file bit by bit ("HTTP/1.0" is a 0 and "HTTP/1.1" is a 1). It uses GET requests so the Blu

Ricardo Ruiz 23 Apr 30, 2022
A tool which is capable of scanning ports as TCP & UDP and detecting open and closed ones.

PortScanner Scan All Open Ports Of The Target IP. A tool which is capable of scanning ports as TCP & UDP and detecting open and closed ones. Clone fro

Msf Nmt 17 Nov 26, 2022
Whoisss is a website information gatharing Tool.

Whoisss Whoisss is a website information gatharing Tool. You can cse it to collect information about website. Usage apt-get update apt-get upgrade pkg

Md. Nur habib 2 Jan 23, 2022
A tiny end-to-end latency testing tool implemented by UDP protocol in Python 📈 .

udp-latency A tiny end-to-end latency testing tool implemented by UDP protocol in Python 📈 . Features Compare with other existing latency testing too

Chuanyu Xue 5 Dec 02, 2022
An curated collection of awesome resources about networking in cybersecurity

An ongoing curated collection of awesome software, libraries, frameworks, talks & videos, best practices, learning tutorials and important practical resources about networking in cybersecurity

Paul Veillard, P. Eng 7 Nov 30, 2022
Client library for relay - a service for relaying server side messages to the client side browsers via websockets.

Client library for relay - a service for relaying server side messages to the client side browsers via websockets.

getme 1 Nov 10, 2021
SocksFlood, a DoS tools that sends attacks using Socks5 & Socks4

Information SocksFlood, a DoS tools that sends attacks using Socks5 and Socks4 Requirements Python 3.10.0 A little bit knowledge of sockets IDE / Code

ArtemisID 0 Dec 03, 2021
Octodns-cloudflare - Cloudflare DNS provider for octoDNS

CloudflareProvider provider for octoDNS An octoDNS provider that targets Cloudfl

octoDNS 6 May 28, 2022
IPV4 network calculation project in Python

Curso de Python 3 do Básico ao Avançado Desafio: Calculando redes IPV4 Criar um programa que obtem um numero de IP com o prefixo da mascara de rede. O

Diego Guedes 3 Jan 21, 2022
Learn how modern web applications and microservice architecture work as you complete a creative assignment

Micro-service Создание микросервиса Цель работы Познакомиться с механизмом работы современных веб-приложений и микросервисной архитектуры в процессе в

Григорий Верховский 1 Dec 19, 2021
Multi-vendor library to simplify CLI connections to network devices

Netmiko Multi-vendor library to simplify CLI connections to network devices Why Netmiko? Network automation to screen-scraping devices is primarily co

Kirk Byers 3k Jan 01, 2023
Easy-to-use sync library for handy proxy parse

Proxy Parser About Synchronous library, for convenient and fast parsing of proxies from different sources. Uses Scrapy as a parser. At the moment the

Michael Mironov 2 Nov 22, 2022
Build surface water network for MODFLOW's SFR Package

Surface water network Creates surface water network, which can be used to create MODFLOW's SFR. Python packages Python 3.6+ is required. Required geop

Mike Taves 20 Nov 22, 2022