, 

NetworkMiner 3.2 Released

NetworkMiner 3.2

NetworkMiner 3.2 parses RADIUS authentication data and extracts more details from the OT/ICS protocols UMAS and IEC-104. The release also improves several existing protocol parsers and fixes file-reassembly issues, helping analysts extract more information from captured network traffic.

OT Protocol Support

NetworkMiner parses many OT/SCADA/ICS communication protocols, such as CIP, COTP, EtherNet/IP, IEC 60870-5-104, Modbus/TCP and UMAS. The parsers for UMAS and IEC-104 have been updated in this release.

The parser for Schneider Electric’s proprietary UMAS protocol in NetworkMiner has been improved. NetworkMiner can now extract data from UMAS commands “Read Physical Address” and “Write Physical Address”. This addition enables analysts to determine not only if data stored in memory of a Schneider Modicon PLC has been modified, but also what changed. This visibility is particularly valuable when performing forensic analysis of OT network traffic after an incident.

UMAS write in NetworkMiner 3.2

Image: Data 0x43 written to address 0x0001FF4E on a Modicon M221 PLC

NetworkMiner can parse most commands defined by the IEC 60870-5-104 protocol, which is used for monitoring and controlling systems in European and Asian power grids.

In this release we’ve added support for IEC-104 command ID 60 (C_RC_TA_1) “Regulating step command with time tag CP56Time2a”, which is used to increase or decrease a data-point by one.

IEC-104 DOWN command extracted by NetworkMiner 3.2

Image: Data-point at IOA 16 decremented using IEC-104 command ID 60

RADIUS

NetworkMiner now includes a parser for the authentication and authorization protocol RADIUS. The parser extracts usernames, passwords (encrypted or hashed), IP addresses, messages and various RADIUS-specific identifiers.

RADIUS credentials extracted with NetworkMiner 3.2

Image: Usernames and password related attributes extracted from RADIUS traffic

RADIUS parameters extracted with NetworkMiner 3.2

Image: Parameters extracted from RADIUS packets

RADIUS traffic for the screenshots above comes from Wireshark’s Sample Captures (radius_localhost.pcap) and Johannes Weber’s Ultimate PCAP.

JA4 Download in NetworkMiner Professional

Many users of NetworkMiner Professional have received an error message saying “JA4 database download failed”.

JA4 database download failed error

This error message is displayed when NetworkMiner Professional tries to download a JA4 database from FoxIO’s website ja4db.com. After consulting FoxIO in 2024, we implemented a solution that automatically retrieved the JA4 database and checked for updates every 30 days.

This database is unfortunately not available for download anymore, which caused users to see “JA4 database download failed” messages. We apologize for any inconvenience this may have caused.

Version 3.2 no longer attempts to download this database.

Bug Fixes and Other Improvements

NetworkMiner 3.2 includes fixes for several bugs reported by Jeliazko Zlatev, which relate to how files are extracted from PCAP data (thank you Jeliazko!). We have also improved parsers for protocols like HTTP, SIP and DNS to extract even more data from the analyzed network traffic to the various tabs on the user interface.

Upgrading to Version 3.2

Users who have purchased NetworkMiner Professional can download version 3.2 from our customer portal, or use the “Check for Updates” feature from NetworkMiner’s Help menu. Users who prefer to use the free and open source version can grab the latest release of NetworkMiner from the official NetworkMiner page.

Posted by Erik Hjelmvik on Wednesday, 07 October 2026 11:30:00 (UTC/GMT)

Tags: #NetworkMiner​ #UMAS​ #IEC-104​ #ICS​ #JA4​

Short URL: https://netresec.com/?b=26Aa0d3