# SNF — Shadow Network Fingerprinting Engine

100% offline. Air-gap-native. Written entirely in Rust.

SNF captures raw packets, reconstructs TCP/UDP flows, and runs them through
14 deterministic protocol analyzers. It detects C2 beacons, DGA domains, DNS
tunnels, lateral movement, data exfiltration, and full ICS/SCADA protocol abuse
across Modbus, S7comm, EtherNet/IP, PROFINET, and DNP3.

Every run produces structured NDJSON with a determinism guarantee — same PCAP,
same config, same version, SHA-256 identical output every time. Court-admissible
evidence bundles built in.

**Zero network calls. Ever. Not a setting. Architecture.**

## Validated Results
- Emotet epoch 3 PCAP — 23 IOC hits, 52 threat matches
- MAWI backbone — 14.9M packets, zero crashes, 332K graph nodes
- nmap standard scan — 1,971 scan events detected


## Links
- Website: https://shadownf.com
- GitHub (open core): https://github.com/padigeltejas/snf-core

Project Activity

See All Activity >

Categories

Packet Sniffers

Follow Shadow Network Fingerprinting Engine

Shadow Network Fingerprinting Engine Web Site

Other Useful Business Software
$300 Free Credits to Build on Google Cloud Icon
$300 Free Credits to Build on Google Cloud

New customers can spin up VMs, build with AI, and query data at no cost.

Put your $300 in credit toward real workloads, then keep building with free monthly usage for 20+ products. No commitment and no charge until you upgrade.
Start Free
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of Shadow Network Fingerprinting Engine!

Additional Project Details

Registered

2026-04-24