pfck - pf check - organizes flow information by host
pfck is a perl script that reads the state table of pf and reports back flows based on a supplied port number. pfck is very handy in ddos attacks to identify who's hitting a host or network on a particular port service, and who they are specifically hitting.
These three tools build Checkpoint, Cisco ASA or Netscreen policys from logfiles. They write dbedit, access-list or set address, set service and set policy commands for the traffic seen in the logs, that can be cut and pasted into the firewalls. WOOT
macf is a MAC-based packet filter. It can be on a machine acting as a firewall, router, bridge, or even a server, and allows operators to "check out" MACs which may then be used for a period of time. Right now, it's on hold for lack of interest.