PolarProxy
PolarProxy is a transparent forward proxy that intercepts and decrypts TLS-encrypted traffic.
It is designed to reveal encrypted communication from malware in controlled environments such as sandboxes, saving the decrypted data as PCAP files for further analysis.

More from NETRESEC
NetworkMiner
Network forensic analysis tool that parses PCAP files and reconstructs hosts, files, sessions, and credentials.
FlowCarp
Behaviour-based protocol identification that detects application-layer protocols regardless of port numbers.
CapLoader
Handle large PCAP datasets fast — view traffic as TCP/UDP flows, filter, and export to other tools.
PacketCache
Free Windows service that continuously buffers captured packets in memory for retrospective analysis.
RawCap
Tiny command-line sniffer for Windows that needs no drivers and can capture localhost traffic.
TrimPCAP
Open-source tool that shrinks PCAP files by over 90% to enable longer traffic retention.
findject
Open-source script that detects injected TCP packets and Man-on-the-Side attacks in HTTP sessions.
SplitCap
Command-line tool that splits large PCAP files by IP, session, or host for faster filtering.