Porthunter
Analyzes PCAP/PCAPNG network captures to detect and classify port scanning techniques.
关于
Porthunter operates as a local Model Context Protocol (MCP) server, specializing in the in-depth analysis of network traffic captures in PCAP/PCAPNG formats. It expertly detects and classifies common port scanning techniques such as SYN, FIN, NULL, and Xmas scans, categorizing them into horizontal or vertical patterns. This powerful tool pinpoints suspicious IP addresses and surfaces the first relevant scan events, enabling rapid identification of threats. Furthermore, Porthunter can enrich public IP addresses with valuable threat intelligence from OTX and GreyNoise, alongside ASN and geolocation data, and even correlate multiple IPs for a consolidated view of potential threats, making it an indispensable asset for cybersecurity investigations and proactive threat hunting.
主要功能
- Analyzes PCAP/PCAPNG network traffic captures for security events
- Detects and classifies common port scanning techniques (SYN, FIN/NULL/Xmas, horizontal/vertical)
- Identifies suspicious IP addresses and extracts the first relevant scan event
- Enriches public IP addresses with threat intelligence (OTX, GreyNoise), ASN, and geolocation data
- Correlates multiple IP addresses to provide consolidated enrichment results
- 0 GitHub stars
使用案例
- Security incident response and forensics on network traffic
- Proactive threat hunting for suspicious scanning activity
- Analyzing network captures to understand attack patterns and origins