findject
findject is an open-source Python script that detects injected TCP packets in HTTP sessions.
It is particularly useful for identifying Man-on-the-Side (MotS) attacks, where an attacker races to inject malicious responses into a victim's traffic.

More from NETRESEC
NetworkMiner
Network forensic analysis tool that parses PCAP files and reconstructs hosts, files, sessions, and credentials.
PolarProxy
Transparent TLS-decrypting proxy that intercepts encrypted malware traffic and saves it as decrypted PCAP.
FlowCarp
Behaviour-based protocol identification that detects application-layer protocols regardless of port numbers.
CapLoader
Handle large PCAP datasets fast — view traffic as TCP/UDP flows, filter, and export to other tools.
PacketCache
Free Windows service that continuously buffers captured packets in memory for retrospective analysis.
RawCap
Tiny command-line sniffer for Windows that needs no drivers and can capture localhost traffic.
TrimPCAP
Open-source tool that shrinks PCAP files by over 90% to enable longer traffic retention.
SplitCap
Command-line tool that splits large PCAP files by IP, session, or host for faster filtering.