0cratesoffline forensics console
so-crates ↗

0crates

Drop a .pcap / .pcapng, or a log (JSON · JSONL · CSV · XML · EVTX) to begin.

Everything runs in your browser. Nothing is uploaded, ever.

No file handy? Download a sample and drop it back in:

PCAP: Ethernet / IPv4 / IPv6 / TCP / UDP / ICMP · DNS, HTTP, TLS SNI · flow reconstruction · ASCII & hex transcripts · stream carving · beaconing detection. Logs: Sigma detection engine, ATT&CK mapping, and multi-source correlation. Drop your SigmaHQ rules or IOC lists to enrich a session.

Inspired by the original so-crates by dougburks ↗