# SNF — Shadow Network Fingerprinting Engine

100% offline. Air-gap-native. Written entirely in Rust.

SNF captures raw packets, reconstructs TCP/UDP flows, and runs them through
14 deterministic protocol analyzers. It detects C2 beacons, DGA domains, DNS
tunnels, lateral movement, data exfiltration, and full ICS/SCADA protocol abuse
across Modbus, S7comm, EtherNet/IP, PROFINET, and DNP3.

Every run produces structured NDJSON with a determinism guarantee — same PCAP,
same config, same version, SHA-256 identical output every time. Court-admissible
evidence bundles built in.

**Zero network calls. Ever. Not a setting. Architecture.**

## Validated Results
- Emotet epoch 3 PCAP — 23 IOC hits, 52 threat matches
- MAWI backbone — 14.9M packets, zero crashes, 332K graph nodes
- nmap standard scan — 1,971 scan events detected


## Links
- Website: https://shadownf.com
- GitHub (open core): https://github.com/padigeltejas/snf-core

Project Activity

See All Activity >

Categories

Packet Sniffers

Follow Shadow Network Fingerprinting Engine

Shadow Network Fingerprinting Engine Web Site

Other Useful Business Software
Our Free Plans just got better! | Auth0 Icon
Our Free Plans just got better! | Auth0

With up to 25k MAUs and unlimited Okta connections, our Free Plan lets you focus on what you do best—building great apps.

You asked, we delivered! Auth0 is excited to expand our Free and Paid plans to include more options so you can focus on building, deploying, and scaling applications without having to worry about your security. Auth0 now, thank yourself later.
Try free now
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of Shadow Network Fingerprinting Engine!

Additional Project Details

Registered

2026-04-24