# SNF — Shadow Network Fingerprinting Engine

100% offline. Air-gap-native. Written entirely in Rust.

SNF captures raw packets, reconstructs TCP/UDP flows, and runs them through
14 deterministic protocol analyzers. It detects C2 beacons, DGA domains, DNS
tunnels, lateral movement, data exfiltration, and full ICS/SCADA protocol abuse
across Modbus, S7comm, EtherNet/IP, PROFINET, and DNP3.

Every run produces structured NDJSON with a determinism guarantee — same PCAP,
same config, same version, SHA-256 identical output every time. Court-admissible
evidence bundles built in.

**Zero network calls. Ever. Not a setting. Architecture.**

## Validated Results
- Emotet epoch 3 PCAP — 23 IOC hits, 52 threat matches
- MAWI backbone — 14.9M packets, zero crashes, 332K graph nodes
- nmap standard scan — 1,971 scan events detected


## Links
- Website: https://shadownf.com
- GitHub (open core): https://github.com/padigeltejas/snf-core

Project Activity

See All Activity >

Categories

Packet Sniffers

Follow Shadow Network Fingerprinting Engine

Shadow Network Fingerprinting Engine Web Site

Other Useful Business Software
Demo Series - Small Business Backup By Veeam Icon
Demo Series - Small Business Backup By Veeam

Learn how to protect your Microsoft 365 data, with simple, actionable tips today.

Watch this on-demand demo series and learn how to protect your Microsoft 365 data with clear, simple, actionable steps that are easy to implement for businesses of all sizes.
Watch Demo Series
Rate This Project
Login To Rate This Project

User Reviews

Be the first to post a review of Shadow Network Fingerprinting Engine!

Additional Project Details

Registered

2026-04-24