NetworkMiner is an open source Network Forensic Analysis Tool (NFAT) for Windows (but also works in Linux / Mac OS X / FreeBSD). NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc. without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates from PCAP files.
NetworkMiner makes it easy to perform advanced Network Traffic Analysis (NTA) by providing extracted artifacts in an intuitive user interface. The way data is presented not only makes the analysis simpler, it also saves valuable time for the analyst or forensic investigator.
NetworkMiner has, since the first release in 2007, become a popular tool among incident response teams as well as law enforcement. NetworkMiner is today used by companies and organizations all over the world.
| NetworkMiner (free edition) | NetworkMiner Professional | |
|---|---|---|
| Live sniffing |
|
|
| Parse PCAP files |
|
|
| Parse PcapNG files |
|
|
| IPv6 support |
|
|
| Extract files from FTP, TFTP, HTTP, HTTP/2, SMB, SMB2, SMTP, POP3, IMAP and LPR traffic |
|
|
| Extract X.509 certificates from SSL encrypted traffic like HTTPS, SMTPS, IMAPS, POP3S, FTPS etc. |
|
|
| Decapsulation of GRE, 802.1Q, PPPoE, VXLAN, OpenFlow, SOCKS, MPLS and EoMPLS |
|
|
| Receive Pcap-over-IP |
|
|
| Runs in Windows and Linux |
|
|
| OS Fingerprinting (*) |
|
|
| JA3 and JA3S hash extraction |
|
|
| Audio extraction and playback of VoIP calls |
|
|
| OSINT lookups of file hashes, IP addresses, domain names and URLs |
|
|
| Port Independent Protocol Identification (PIPI) |
|
|
| User Defined Port-to-Protocol Mappings (decode as) |
|
|
| Export to CSV / Excel / XML / CASE / JSON-LD |
|
|
| Configurable file output directory |
|
|
| Configurable time zone (UTC, local or custom) |
|
|
| Geo IP localization (**) |
|
|
| DNS Whitelisting (***) |
|
|
| Advanced OS fingerprinting |
|
|
| Web browser tracing (4:10 into this video) |
|
|
| Online ad and tracker detection |
|
|
| Host coloring support |
|
|
| Command line scripting support |
(through NetworkMinerCLI)
|
|
| Price | Free | $ 1200 USD |
|
Download NetworkMiner |
|
|
|
* Fingerprinting of Operating Systems (OS) is performed by using databases from Satori and p0f ** This product includes GeoLite data created by MaxMind, available from http://maxmind.com/ *** Domain names in the DNS tab are checked against the Alexa top 1,000,000 sites |
||
NetworkMiner can extract files, emails and certificates transferred over the network by parsing a PCAP file or by sniffing traffic directly from the network.
NetworkMiner showing files extracted from sniffed network traffic to disk
NetworkMiner showing thumbnails for images extracted to disk
User credentials (usernames and passwords) for supported protocols are extracted by NetworkMiner and displayed under the "Credentials" tab. The credentials tab sometimes also show information that can be used to identify a particular person, such as user accounts for popular online services like Gmail or Facebook.
Another very useful feature is that the user can search sniffed or stored data for keywords. NetworkMiner allows the user to insert arbitrary string or byte-patterns that shall be searched for with the keyword search functionality.
NetworkMiner Professional can be delivered either as an Electronic Software Download (ESD) or shipped physically on a USB flash drive. The product is exactly the same, regardless of delivery method. NetworkMiner is a portable application that doesn't require any installation, which means that the USB version can be run directly from the USB flash drive. However, we recommend that you copy NetworkMiner to the local hard drive of your computer in order to achieve maximum performance.
ยป How To Buy NetworkMiner Professional ยซ
The latest version of NetworkMiner can be downloaded from:
ยป https://www.netresec.com/?download=NetworkMiner ยซ (executable application)
ย ย ย SHA256 hash: df4057eb0256dab23dee9c248d60db11d46b20d344d8769ca0e5768afd76dd3f
ยป https://www.netresec.com/?page=NetworkMinerSourceCode ยซ (source code)
ย ย ย SHA256 hash: 7afaf30e2907e9df3cf68fce1869b04e8bd667e5ac4619cea2a014445a38d330
For older releases of NetworkMiner (prior to version 2.0), please visit the NetworkMiner page on SourceForge:
http://sourceforge.net/projects/networkminer/files/networkminer/
However, please note that we no longer release new versions of NetworkMiner on SourceForge.
There are also several blog posts about NetworkMiner on the NETRESEC Network Security Blog:
โ