Network Analysis Software WLSAT logoClose this page   Print this page

Med Blue Rule

Windows Wired Environment Productivity tools:
 

OpenOffice.org logo

OpenOffice — Windows

  • OpenOffice.org is both a multi-platform and multi-lingual office suite and an open-source project.
  • Compatible with all other major office suites, the product is free to download, use, and distribute.
SnagIt box  

SnagIt 8 Screen Capture and Sharing

  • All the screen capture and editing functionality you’ll ever need, in one simply powerful program.
  • Using SnagIt, you can select and capture anything on your screen, then easily add text, arrows, or effects, and save the capture to a file or share it immediately by e-mail or IM.
  • Capture and share an article, image, or Web page directly from your screen. Or, capture and share any part of any application that runs on your PC.
  • Using SnagIt you’ll immediately notice all the ways it makes your daily tasks much more efficient and enjoyable.
SystemLifeguard  

System LifeGuard 2
Faster computer in just seconds with these essential tools!

  • PC Cleaner
  • Program Uninstaller
  • Registry Cleaner
  • System tweaker
  • Internet privacy
  • System backup & restore with a FTP backup option
  • Scheduler
  • Startup manager
  • Shutdown manager
  • Disk Defragmenter
  • Shred all unnecessary files
  • Detects duplicates, old and large files

Med Blue Rule

Windows Wired Environment software tools:
 

Northwest Performance Software banner

 

NetScanTools Pro

  • Quickly gathers information about Internet or local LAN users, IP addresses, ports, and other network specifics
  • Automates Internet investigation research requiring multiple tools
  • Produces clear, concise results reports in the format that you prefer
  • Enhances many commonly available network tools.
  • A Security Testing Solution
    • ARP Scan can rapidly show IPv4 connected devices on your LAN using ARP.
    • NetScanner can show IPv4 connected devices on any reachable IPv4 network using ping sweep.
    • Promiscuous Mode Scanner can help show devices listening to or snooping on packet traffic in your LAN.
    • Port Scan can check for unauthorized or unintentionally installed services on IPv4 connected computers.
    • Packet Generator (TCP and UDP), Ping, Traceroute, OS Fingerprinting, NetScanner and the custom ICMP packet generator can test systems and firewalls for vulnerabilities and exposed ports.
    • NetBIOS Info can look for open (writable) Windows shares on your LAN and to check for user lists and other exposed account info on Windows targets.
    • Cache Forensics can show Internet Explorer history, cache and cookie information plus it can show Protected Storage information containing passwords and IE auto-complete data.
  • A Network Information Gathering and Discovery Solution
    • IP Packet Viewer can show the IP packets going by your wired ethernet card. This packet capture program has the ability to preserve packet data for future analysis and export packets to other programs.
    • NetScanner is a ping sweep utility that includes DNS queries, NetBIOS queries for NetBIOS name table and MAC address. Also can query ARP cache information for automatic updating of the IP/MAC address management database.
    • IP and MAC address associations found using NetScanner, ARP, SNMP, and NetBIOS can be automatically updated and maintained in a database.
    • NetBIOS share detection (including 'writable' share status frequently abused by worms and viruses)
    • Many SNMPv1 tools such as walk, get, set and several advanced queries like remote ARP cache.
    • Port Scanner tool that has several different ways to see if a TCP or UDP port is being used on a machine.
    • DNS Checking and Testing includes NSLOOKUP with 43 record query options. We also have DIG. Check zone transfers with List Domain or Dig w/AXFR. DNS Validation (IP to Hostname to IP mapping check) in the HyperTrans tool.
    • Email Address Validation and Open SMTP Relay Checking.
    • Numerous other utilities like Subnet Calculator, TTCP for network speed checking, DHCP server discovery, Ping, Traceroute including firewall penetrating TCP and UDP modes, Whois/rwhois featuring automatic whois server selection, IP/MAC address database, and obscured URL decoding.
  • A Training Solution
    • NetScanTools Pro is a great tool to help train people on the workings of various TCP/IP utilities. You can also use it to demonstrate security vulnerabilities and some of the common techniques used to map and access unsecure networks and machines.
    • NetScanTools Pro is a used in network security training classes by Laura Chappell of the Protocol Analysis Institute.

 

NetResidentNetResident is a network content monitoring program that captures, stores, analyzes, and reconstructs network events such as e-mail messages, Web pages, downloaded files and instant messages.

  • NetResident uses advanced monitoring technology to capture the data on the network, saves it to a database, reconstructs it, and displays this content in an easy-to-understand format.
  • While NetResident is similar to network analyzers in many respects, it focuses on high-level protocols that are used to transfer content over the Internet or LAN.
  • NetResident is used by network administrators to enforce IT policy, by parents to monitor their children’s communication on the Internet, and by forensic experts to gain crucial information.
Invisible Secrets  

Invisible Secrets 4 is shell integrated and offers a wizard that guides you through all the necessary steps needed to protect your data. It features:

  • Steganography — not only encrypt your data and files for safe keeping or for secure transfer across the net, but also hide them in places that appear totally innocent, such as picture or sound files, or web pages.
  • Cryptography — encryption is the translation of data into a secret code. To read an encrypted file, you must know the correct password (or key) that allows you to decrypt it. File encryption is based on encryption algorithms which translate data into a secret code. Invisible Secrets 4 features strong file encryption algorithms (including AES - Rijndael).
  • Password Manager — a management solution that stores all your passwords securely and helps you create secure passwords.
  • File Destroyer — a shredder that helps you destroy files and folders beyond recovery.
  • Internet Trace Destroyer — destroys the Internet Traces left behind on your computer while you browse the Internet: internet cache, cookies, recently typed URLs, Internet Explorer History and Most Recently Used Documents / Applications.
  • Cryptboard — add files to the Cryptboard basket and you can perform various security operations on them in a single step, anytime you want. The Cryptboard is accessible through the context menu, the tray icon, or from the main program.
  • Email Package Encryption — create an executable "self-decrypting" package with encrypted, compressed content. The package can be sent by email or other transfer method. All the receiver needs to decrypt the package at destination is the correct password.
  • IP-to-IP Password Transfer — Securely exchange a password between two computers using an encrypted internet connection.
  • Application Locker — allows you to password protect certain applications to restrict access. Invisible Secrets will encrypt the application. When you want to run a locked application you need to provide the password. Invisible Secrets will decrypt the application and will allow you to run it. After the application is closed, Invisible Secrets re-encrypts it in the background. To quickly open the list of locked application you can define a hot-key, or use the tray menu.
Can & Abel  

Cain & Abel is a password recovery tool for Microsoft Operating Systems.

  • It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary, Brute-Force and Cryptanalysis attacks, recording VoIP conversations, decoding scrambled passwords, revealing password boxes and analyzing routing protocols.

Ettercap logo

 

Ettercap is a suite for "man in the middle" attacks on a LAN.

  • Ettercap features sniffing of live connections, content filtering on the fly and many other interesting tricks.
  • Ettercap supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis.

AirPcap logo

 

AirPcap w/Wireshark – CACE Technologies

AirPcap is the first open, affordable and easy to deploy WLAN (802.11b/g) packet capture solution for the Windows platform. AirPcap comes as a USB 2.0 adapter, and it's been fully integrated with WinPcap and Wireshark: it enables you to capture and analyze 802.11b/g wireless traffic, including control frames, management frames and power information, using Wireshark on your Windows laptop.

Complete Visibility on Your Wireless Networks

The AirPcap adapter, together with the Wireshark Network Analyzer, gives you a detailed view on the 802.11 traffic, including control frames (ACK, RTS, CTS), management frames (Beacon, Probe requests and responses, Association/Disassociation, Authentication/Deauthentication) and data frames. The captured frames include the 802.11 Frame Check Sequence, and it's possible to capture frames with an invalid FCS to spot remote access points with a weak signal.

You will be able to specify the capture channel and see all the traffic it carries, even if the channel is shared by multiple access points. The AirPcap adapter can be configured with one or more WEP keys, so that you will have the option to see (and filter on) unencrypted traffic in Wireshark.

The AirPcap adapter captures per-packet power and rate information. This is useful for mapping your network, detecting weak signal areas, and measuring the transmission efficiency of the stations.

Med Blue Rule

Configured wireless environment tools for Windows include:

NetStumbler logo

 

NetStumbler is a tool for Windows that allows you to detect Wireless
Local Area Networks (WLANs) using 802.11b, 802.11a and 802.11g.

  • Verify that your network is set up the way you intended
  • Find locations with poor coverage in your WLAN
  • Detect other networks that may be causing interference on
    your network
  • Detect unauthorized "rogue" access points in your workplace
  • Help aim directional antennas for long-haul WLAN links
  • Use it recreationally for WarDriving

Retina WiFi Scanner

eEye logo

 

The Retina WiFi Scanner is a comprehensive wireless detection tool that incorporates Retina Network Security Scanner technology to discover all active wireless devices and connections on a company network

  • Installed on a Windows laptop or desktop PC, Retina WiFi enables security and IT professionals to detect wireless access devices, scan for service and generate detailed reports on their wireless security
  • Retina WiFi Scanner for Windows can push data to eEye's REM Security Management Console to integrate into a company’s overall vulnerability management system

TamoSoft logo

 

CommView WiFiCommView for WiFi is a powerful wireless network monitor and analyzer for 802.11 a/b/g networks. Loaded with many user-friendly features, CommView for WiFi combines performance and flexibility with an ease of use unmatched in the industry.

  • CommView for WiFi captures every packet on the air to display important information such as the list of access points and stations, per-node and per-channel statistics, signal strength, a list of packets and network connections, protocol distribution charts, etc.
  • By providing this information, CommView for WiFi can help you view and examine packets, pinpoint network problems, perform site surveys, and troubleshoot software and hardware.



network toolkit logo

open source tools  

Open Source Tools On Windows

Open Source security and network tools are the most powerful in the world, but for many running Linux isn't practical. With The Network Toolkit, Windows administrators have an easy method to take advantage of network tools like Nmap and Wireshark. In addition to security and networking tools, The Network Toolkit includes the Cygwin Shell environment, so administrators who are used to the Unix shell environment will have one at whatever Windows system they find themselves

portable

 

Portable

No other product makes it so easy to carry your tools with you. Unlike other network troubleshooting software, the traditional software installer process is not needed because of unique technology in The Network Toolkit. While administrators could go to the net and download an Open Source tool like Wireshark and all the necessary libraries, with the Network Toolkit all the leg work is already done.

updates

 

Regular Updates

The Network Toolkit is the only product that allows for easy and regular updates to all the important Open Source networking and security tools on Windows. With key Open Source developers on its staff, CACE Technologies is uniquely positioned to know when there are significant defects or security issues. Customers of The Network Toolkit can stay a step ahead of potential problems by purchasing the annual subscription service.

no trace

 

No Trace Left

After running a tool from The Network Toolkit on a USB drive or CDROM, no trace is left on the machine. All temporary files, Registry Keys, and other remnants are removed. For forensic computer specialists this makes the toolkit particularly useful, since they can leave the investigated machine in the same state as they found it. With traditional Windows software installers, software has to be removed using the Add/Remove Software tool in control panel. For software run from The Network Toolkit, once the program is closed, all traces are gone from the system.


air defense

 

AirDefense Mobile™ is a complementary solution to the AirDefense Enterprise monitoring platform, giving enterprises an AirDefense-powered mobile product to perform a real-time snapshot of all WLAN infrastructure and activity (802.11 a/b/g). This must-have tool provides wireless device inventory, threat index analysis, location tracking, advanced rogue management and automated protection.

AirDefense Mobile provides a real-time snapshot of all 802.11 a/b/g wireless infrastructure including:

  • Real Time Device Discovery and Connection Analysis
  • Advanced Rogue Management with Threat Indicators for rogue devices
  • Real-time Threat Detection and Alarm Expert Help
  • Advanced Location Tracking including Triangulation positioning
  • Automated Protection with Termination Capabilities
  • Live View for Traffic Analysis
  • Wireless Network Usage Statistics and Health Analysis
  • Capture file playback for off-site analysis and reporting
  • Advanced Diagnostics tools for Troubleshooting
  • Reporting Capabilities


AirPcap

 

AirPcap w/Wireshark – CACE Technologies

AirPcap is the first open, affordable and easy to deploy WLAN (802.11b/g) packet capture solution for the Windows platform. AirPcap comes as a USB 2.0 adapter, and it's been fully integrated with WinPcap and Wireshark: it enables you to capture and analyze 802.11b/g wireless traffic, including control frames, management frames and power information, using Wireshark on your Windows laptop.



spacemonger logo

treemaps

chart

 

SpaceMonger, the best-kept secret of computer-room system-administrators the world over. Imagine, if you will, being able to fly over the mountains and hills and valleys of your drive in an airplane, elegantly soaring over the data and seeing from above how it all fits together. No matter how messy your data, no matter how jam-packed your drive, SpaceMonger can give you that bird's-eye-view you've wished for. With the magic of treemaps, as well as charts and graphs aplenty, you'll never be lost in your data again!

Look --- and touch. Showing you the data is good, but SpaceMonger can do more. It includes powerful tools for manipulating the data, too, including standard built-in operations like deleting, copying, and moving files, and SpaceMonger even knows when you use other programs to alter files!


omnipeek logo

 

 

OmniPeek Personal demonstrates what a powerful, well-designed network analysis tool is capable of accomplishing. Ideal for people who need visibility into network traffic on non-commercial networks, OmniPeek Personal allows users to experience how the OmniAnalysis Platform pinpoints and analyzes network problems. OmniPeek Personal provides an introduction to the superior high-level views of WildPackets Expert Analysis which make the identification of network problems simple and quick.

  • Analyze traffic from a local network segment
  • View “top talkers,” and drill down to see which nodes are communicating, which protocols and sub-protocols are being transmitted, and which traffic characteristics are affecting network performance
  • Change filters on the fly without having to stop and restart packet captures
  • View packet-stream based analytics by conversation pair, instantly locating network events

WiFi Hopper

 

WiFi Hopper is a WLAN utility that combines the features of a Network Discovery and Site Survey tool with a Connection Manager.

Sporting a comprehensive arsenal of network details, filters, RSSI graphing and built-in GPS support, WiFi Hopper is invaluable for identification and advanced characterization of neighboring wireless devices.
Additionally, WiFi Hopper can connect to unsecured, WEP, WPA-PSK and WPA2-PSK networks directly from within the application. With editable network profiles and dedicated Connection Manager execution mode, WiFi Hopper can be used as a significantly more transparent replacement for Windows and manufacturer-provided wireless clients.

WiFi Hopper encompasses a feature set aimed for a wide variety of audiences including Wireless Network Administrators, Security Professionals, Programmers, QA Engineers and Power Users.

Med Blue Rule

Linux Wired Productivity tools:
 

OpenOffice.org logo

OpenOffice - Linux

  • OpenOffice.org is both a multi-platform and multi-lingual office suite and an open-source project.
  • Compatible with all other major office suites, the product is free to download, use, and distribute.

Med Blue Rule

BackTrack security collection - Wired
 
Remote Exploit logo
Backtrack logo

Footprinting

  • Greenwhich
  • Whois
  • Gnetutil (Network Utilities)
  • Itrace (ICMP traceroute)
  • Tctrace (TCP traceroute)
  • Traceroute
  • DNSwalk (DNS verification)
  • Dig (DNS lookup)
  • Host (DNS lookup)
  • NSTXCD (IP over DNS client)
  • NSTXD (IP over DNS server)
  • Oxyman (DNS tunnel)
  • Curl (URL transfer)
  • Elinks (Console web browser)
  • Konqueror (Web browser)
  • Socat (Socket Cat)
  • Stunnel (Universal SSL tunnel)
  • Arpfetch (SNMP ARP/IP fetcher)
  • SNMPWalk (SNMP tree walk)
  • TKMib (Mib browser)
  • GQ (LDAP browser)
  • Komba2 (KDE SMB browser)
  • LinNeighborhood (Graphical SMB browser)
  • Net utils (NET utilities)
  • SMBClient (SMB client)
  • SMBGet (SMB downloader)
  • Smb4K (SMB share browser)
  • Xsmbrowser (Graphical SMB browser)
  • nmblookup (Netbios name lookup)
  • smbdumpusers (User browser)
  • smbgetserverinfo (Get server info)
  • Cheops (Network neighborhood)
  • NTP-fingerprint (Detection based on ntp fingerprint)
  • Nmap (Network scanner)
  • NmapFE (Graphical network scanner)
  • P0f (Passive OS fingerprinting)
  • Queso (OS detection)
  • XProbe2 (OS detection)

Scanning

  • Cisco global exploiter (Cisco scanner)
  • Cisco torch (Cisco oriented scanner)
  • ExploitTree search (ExploitTree collection)
  • Metasploit (Metasploit commandline)
  • Metasploit (Metasploit console GUI)
  • Metasploit (Metasploit web interface)
  • Nessus (Security Scanner)
  • Raccess (Remote scanner)
  • Httprint (Webserver fingerprinting)
  • Nikto (Webserer scanner)
  • Stunnel (Universal SSL tunnel)
  • Cheops (Network neighborhood)
  • GTK-Knocker (Simple GUI portscanner)
  • IKE-Scan (IKE scanner)
  • Knocker (Simple portscanner)
  • Netenum (Pingsweep)
  • Netmask (Requests netmask)
  • Nmap (Network scanner)
  • NmapFE (Graphical network scanner)
  • Proxychains (Proxifier)
  • Scanrand (Stateless scanner)
  • Timestamp (Requests timestamp)
  • Unicornscan (Fast port scanner)
  • Isrscan (Source routed packets scanner)
  • Amap (Application identification)
  • Bed.pl (Application fuzzer)
  • SNMP-Fuzzer (SNMP protocol fuzzer)
  • ScanSSH (SSH identification)
  • Nbtscan (Netbios scanner)
  • SMB-Nat (SMB access scanner)
  • Ozyman (DNS tunnel)
  • Ass (Autonomous system scanner)
  • Protos (Protocol identification)

Password cracker

  • BKHive (SAM recovery)
  • Fcrackzip (Zip password cracker)
  • John (Multi-purpose password cracker)
  • Default password list
  • Nasty (GPG secret key cracker)
  • Rainbowcrack (Hash cracker)
  • Samdump2 (SAM file dumper)
  • Wordlists (Collection of wordlists)
 

Analyzer

  • AIM-SNIFF (AIM sniffer)
  • Driftnet (Image sniffer)
  • Mailsnarf (Mail sniffer)
  • Paros (HTTP interception proxy)
  • URLsnarf (URL sniffer)
  • smbspy (SMB sniffer)
  • Etherape (Network monitor)
  • Ethereal (Network analyzer)
  • Ettercap (Sniffer/Interceptor/Logger)
  • Hunt (Sniffer/Interceptor)
  • IPTraf (Traffic monitor)
  • NGrep (Network grep)
  • NetSed (Network edit)
  • SSLDump (SSLv3/TLS analyzer)
  • Sniffit (Sniffer)
  • TcPick (Packet stream editor)
  • Dsniff (Password sniffer)

Spoofing

  • Arpspoof (ARP spoofer)
  • Macof (ARP spoofer/generator)
  • Nemesis-ARP (ARP packet generator)
  • Nemesis-Ethernet (Ethernet packet generator)
  • CDP (CDP generator)
  • DNSSpoof (DNS spoofer)
  • Nemesis-DNS (DNS packet generator)
  • DHCPX (DHCP flooder)
  • Hping2 (Packet generator)
  • ICMPRedirect (ICMP redirect packet generator)
  • ICMPUSH (ICMP packet generator)
  • Nemesis-ICMP (ICMP packet generator)
  • Packit (Traffic inject/modify)
  • TcPick (Packet stream editor)
  • Yersinia (Layer 2 protocol injector)
  • Fragroute (Egress rewrite)
  • HSRP (HSRP generator)
  • IGRP (IGRP injector)
  • IRDP (IRDP generator)
  • IRDPresponder (IRDP response generator)
  • Nemesis-IGMP (IGMP generator)
  • Nemesis-RIP (RIP generator)
  • File2Cable (Traffic replay)
  • Fragrouter (IDS evasion toolkit)
  • Nemesis-IP (IP packet generator)
  • Nemesis-TCP (TCP packet generator)
  • Nemesis-UDP (UDP traffic generator)
  • SendIP (IP packet generator)
  • TCPReplay (Traffic replay
  • Etherwake (Generate wake-on-LAN)

Bruteforce

  • ADMsnmp (SNMP bruteforce)
  • Guess-who (SSH bruteforc)
  • Hydra (Multi purpose bruteforce)
  • K0ldS (LDAP bruteforce)
  • Obiwan III (HTTP bruteforce)
  • SMB-Nat (SMB access scanner)
  • TFTP-bruteforce
  • VNCrack (VNC bruteforce)
  • Xhydra (Graphical bruteforcer

Forensics

  • Autopsy (Forensic GUI)
  • Recover (Ext2 file recovery)
  • Testdisk (Partition scanner)
  • Wipe (Securely delete files)

Honeypot

  • IMAP
  • POP3
  • Honeyd (Honeypot)
  • IISEmulator (Honeypot)
  • Tinyhoneypot (Simple honeypot)

Med Blue Rule

BackTrack security collection - Wireless
 
Remote Exploit logo


backtrack logo

Wireless tools installed

  • AFrag
  • ASLeap
  • Air Crack
  • Air Decap
  • Air Replay
  • Airmon Script
  • Airpwn
  • AirSnarf
  • Airbase
  • Airodump
  • Airoscript
  • Airsnort
  • CowPatty
  • FakeAP
  • GenKeys
  • Genpmk
  • Hotspotter
  • Karma
  • Kismet
  • Load IPW3945
  • Load acx100
  • MDK2
 

 

  • MDK2 for Broadcom
  • MacChanger
  • Unload Drivers
  • Wep_crack
  • Wep_decrypt
  • WifiTap
  • Wicrawl
  • Wlassistant

Bluetooth tools installed

  • Bluebugger
  • Blueprint
  • Bluesnarfer
  • Btscanner
  • Carwhisperer
  • CuteCom
  • Ghettotooth
  • HCIDump
  • Ussp-Push

Med Blue Rule

  HOT Labs logo
Close this page Print this page