...SNF captures raw packets, reconstructs TCP/UDP flows, and runs them through
14 deterministic protocol analyzers. It detects C2 beacons, DGA domains, DNS
tunnels, lateral movement, data exfiltration, and full ICS/SCADA protocol abuse
across Modbus, S7comm, EtherNet/IP, PROFINET, and DNP3.
Every run produces structured NDJSON with a determinism guarantee — same PCAP,
same config, same version, SHA-256 identical output every time. Court-admissible
evidence bundles built in.
**Zero network calls. Ever. Not a setting. Architecture.**
## Validated Results
- Emotet epoch 3 PCAP — 23 IOC hits, 52 threat matches
- MAWI backbone — 14.9M packets, zero crashes, 332K graph nodes
- nmap standard scan — 1,971 scan events detected
## Links
- Website: https://shadownf.com
- GitHub (open core): https://github.com/padigeltejas/snf-core