NetworkMiner logo


NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows (but also works in Linux / Mac OS X / FreeBSD). NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc. without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates from PCAP files.

NetworkMiner makes it easy to perform advanced Network Traffic Analysis (NTA) by providing extracted artifacts in an intuitive user interface. The way data is presented not only makes the analysis simpler, it also saves valuable time for the analyst or forensic investigator.

NetworkMiner has, since the first release in 2007, become a popular tool among incident response teams as well as law enforcement. NetworkMiner is today used by companies and organizations all over the world.

NetworkMiner (free edition) NetworkMiner Professional
Live sniffing Yes Yes
Parse PCAP files Yes Yes
Parse PcapNG files Yes
IPv6 support Yes Yes
Decapsulation of GRE, 802.1Q, PPPoE, VXLAN, OpenFlow, SOCKS, MPLS and EoMPLS Yes Yes
Receive Pcap-over-IP Yes Yes
OS Fingerprinting (*) Yes Yes
Port Independent
Protocol Identification (PIPI)
Export results to CSV / Excel / XML Yes
Configurable file output directory Yes
Geo IP localization (**) Yes
DNS Whitelisting (***) Yes
Advanced OS fingerprinting Yes
Web browser tracing Yes
Online ad and tracker detection Yes
Host coloring support Yes
Command line scripting support Yes (through NetworkMinerCLI)
PCAP parsing speed (****) 0.83 MB/s 0.77 MB/s (GUI version)
1.27 MB/s (command line version)
Price Free $ 900 USD
Download NetworkMiner (free edition) Buy NetworkMiner Professional
* Fingerprinting of Operating Systems (OS) is performed by using databases from Satori and p0f
** This product includes GeoLite data created by MaxMind, available from
*** Domain names in the DNS tab are checked against the Alexa top 1,000,000 sites
**** Measured by loading dump.eth0.1059726000 from Defcon 11 (189MB) on a standard laptop with Intel Core i7 CPU (3.1GHz).

NetworkMiner can extract files, emails and certificates transferred over the network by parsing a PCAP file or by sniffing traffic directly from the network. This functionality can be used to extract and save media files (such as audio or video files) which are streamed across a network from websites such as YouTube. Supported protocols for file extraction are FTP, TFTP, HTTP, SMB, SMB2, SMTP, POP3 and IMAP.

NetworkMiner extracted files

NetworkMiner showing files extracted from sniffed network traffic to disk

NetworkMiner extracted images and pictures

NetworkMiner showing thumbnails for images extracted to disk

User credentials (usernames and passwords) for supported protocols are extracted by NetworkMiner and displayed under the "Credentials" tab. The credentials tab sometimes also show information that can be used to identify a particular person, such as user accounts for popular online services like Gmail or Facebook.

NetworkMiner Professional USB flash drive

Another very useful feature is that the user can search sniffed or stored data for keywords. NetworkMiner allows the user to insert arbitrary string or byte-patterns that shall be searched for with the keyword search functionality.

NetworkMiner Professional comes installed on a specially designed USB flash drive. You can run NetworkMiner directly from the USB flash drive since NetworkMiner is a portable application that doesn't require any installation. We at Netresec do, however, recommend that you copy NetworkMiner to the local hard drive of your computer in order to achieve maximum performance.

» Buy NetworkMiner Professional «

Download NetworkMiner

The latest version of NetworkMiner can be downloaded from:
» « (executable application)
» « (source code)

For older releases of NetworkMiner (prior to version 2.0), please visit the NetworkMiner page on SourceForge:

However, please note that we no longer release new versions of NetworkMiner on SourceForge.

Change Log

Version Release Date Major Improvements
NetworkMiner 2.1.1 2017-01-19 Improved HTTP parser
NetworkMiner 2.1 2017-01-11 New protocols: POP3, IMAP, VXLAN, OpenFlow and SOCKS.
NetworkMiner 2.0 2016-02-09 New protocols: SMB2 and Modbus/TCP.
NetworkMiner 1.6 2014-06-16 Improved SMTP and DNS parsing.
NetworkMiner 1.5 2013-08-07 New protocols: PPPoE and LLMNR, fixed two vulnerabilities.
NetworkMiner 1.4 2012-08-16 New protocol: IEC 60870-5-104.
NetworkMiner 1.3 2012-04-12 Username and password from HTTP Digest Authentication (RFC 2617).
NetworkMiner 1.2 2011-11-19 New protocol: GRE, platform independent (works in Linux, Mac OSX etc).
NetworkMiner 1.1 2011-09-15 New protocol: PPP. Screen resolution, color depth, browser language and flash version extracted from Google Analytics.

More Information

There are also several blog posts about NetworkMiner on the NETRESEC Network Security Blog: