NetworkMiner
VerifiedOpen source network forensics tool extracting files, images, emails and passwords from PCAP captures
See all screenshots - Deployment On Premise
- Starting price Free
- Free trial Available
- Best for Freelancers, Small Business, Medium Business
What is NetworkMiner?
NetworkMiner is an open source network forensics tool from Netresec that extracts artifacts including files, images, emails and passwords from captured network traffic in PCAP files, and can also capture live traffic by sniffing a network interface, aggregating detailed information about each IP address in the analysed traffic.
The artifact extraction approach is what separates this from a conventional packet analyser, and the difference is one of orientation rather than capability.
A traditional packet analyser presents traffic as a chronological list of packets, which is the correct view for diagnosing a protocol problem and close to useless for answering an investigative question. An investigator does not want to know that packet 84,312 carried a TCP segment. They want to know which files crossed the network, which credentials were transmitted, and which hosts were involved.
NetworkMiner reassembles the traffic into those artifacts directly, so the analyst is presented with the files themselves rather than with the packets that carried them. That reordering saves enormous time in exactly the situations where time matters most.
Host-centric aggregation reinforces the same orientation. Organising everything known about each IP address into one view answers the question an investigator actually asks, which is what this machine did, rather than what happened in this time window.
Password extraction deserves a note of caution alongside its usefulness. It demonstrates plainly why unencrypted protocols are indefensible on any modern network, since credentials sent in clear text can be recovered by anyone with a capture. As a tool it is dual-use in the ordinary way that forensics tools are, and its legitimate use is on traffic you are authorised to examine.
Working from PCAP files rather than requiring live capture suits investigative workflow, where the capture was taken by somebody else, possibly weeks earlier, and analysis happens on a separate machine.
NetworkMiner is published as open source, with a commercial professional edition offered by Netresec.
Key Features of NetworkMiner
- Network forensics artifact extraction
- File carving from network traffic
- Image extraction
- Email reconstruction
- Credential recovery from clear-text protocols
- Host-centric IP address aggregation
- PCAP and PcapNG file analysis
- Live interface sniffing
- Operating system fingerprinting
- Open source with a professional edition
NetworkMiner Pricing
Open source edition
Free
Free open source network forensics tool available for download.
Professional edition
Quoted on request
Commercial edition from Netresec with additional capability, priced through the vendor.
NetworkMiner Specifications
- Deployment
- On Premise
- Desktop
- Windows
- Linux
- Built for
- Freelancers
- Small Business
- Medium Business
- Large Enterprise
- Support
- Public API
- No
- Free trial
- Yes
- Free plan
- No
- Runs in browser
- No
- Customisable
- No
- Website
- netresec.com
NetworkMiner Comparisons
NetworkMiner Reviews
No reviews yet
Used NetworkMiner? Share your experience and help other buyers decide.