OpenAttackDefenseTools / tulip

Network analysis tool for Attack Defence CTF
GNU General Public License v3.0
264 stars 36 forks source link

[feature request] show incomplete TCP streams #10

Open erdnaxe opened 1 year ago

erdnaxe commented 1 year ago

During FAUST CTF 2022 there were one service called Ghost which was sending SYN to the vulnbox. This could be spotted using WireShark.

This is hard to solve as we mostly don't want to bloat Tulip, but maybe something could be done to represent "incomplete TCP flows and UDP" data from PCAPs inside Tulip?