0% found this document useful (0 votes)
25 views6 pages

Download NetworkMiner for Windows

NetworkMiner is an open source network forensic analysis tool that can be used to perform passive network sniffing and packet capture to detect operating systems, sessions, hostnames, and open ports without generating network traffic. It parses PCAP files for offline analysis and can reconstruct transmitted files and certificates. NetworkMiner extracts artifacts like files, emails, and certificates from network traffic in an intuitive interface, saving time for analysts. It comes in free and paid professional versions.

Uploaded by

Telekom Files
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
25 views6 pages

Download NetworkMiner for Windows

NetworkMiner is an open source network forensic analysis tool that can be used to perform passive network sniffing and packet capture to detect operating systems, sessions, hostnames, and open ports without generating network traffic. It parses PCAP files for offline analysis and can reconstruct transmitted files and certificates. NetworkMiner extracts artifacts like files, emails, and certificates from network traffic in an intuitive interface, saving time for analysts. It comes in free and paid professional versions.

Uploaded by

Telekom Files
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

NetworkMiner - The NSM and Network Forensics Analysis Tool ⛏ (netresec.

com)

NetworkMiner is another analytical tool that acts on feeds from Wireshark. This tool
comes in both a free and paid version

NetworkMiner
NetworkMiner is an open source Network Forensic Analysis Tool (NFAT) for Windows
(but also works in Linux / Mac OS X / FreeBSD). NetworkMiner can be used as a
passive network sniffer/packet capturing tool in order to detect operating systems,
sessions, hostnames, open ports etc. without putting any traffic on the network.
NetworkMiner can also parse PCAP files for off-line analysis and to
regenerate/reassemble transmitted files and certificates from PCAP files.

NetworkMiner makes it easy to perform advanced Network Traffic Analysis (NTA) by


providing extracted artifacts in an intuitive user interface. The way data is presented not
only makes the analysis simpler, it also saves valuable time for the analyst or forensic
investigator.

NetworkMiner has, since the first release in 2007, become a popular tool among incident
response teams as well as law enforcement. NetworkMiner is today used by companies
and organizations all over the world.

NetworkMiner NetworkMiner
Free Edition Professional
Live sniffing ✅ ✅
Parse PCAP files ✅ ✅
Parse PcapNG files ✅
Parse ETL files ✅ ✅
Network Packet Carver ✅
IPv6 support ✅ ✅
Extract files from FTP, ✅ ✅
TFTP, HTTP, HTTP/2,
SMB, SMB2, SMTP,
POP3, IMAP and LPR
traffic
Extract X.509 ✅ ✅
certificates from SSL
encrypted traffic like
HTTPS, SMTPS,
IMAPS, POP3S, FTPS
etc.
Decapsulation of GRE, ✅ ✅
802.1Q, PPPoE,
VXLAN, OpenFlow,
SOCKS, MPLS,
EoMPLS and ERSPAN
Receive Pcap-over-IP ✅ ✅
Runs in Windows ✅ ✅
and Linux
OS Fingerprinting (*) ✅ ✅
JA3 and JA3S hash ✅ ✅
extraction
Audio extraction and ✅
playback of VoIP calls
OSINT lookups of file ✅
hashes, IP addresses,
domain names and
URLs
Port Independent ✅
Protocol Identification
(PIPI) (**)
User Defined Port-to- ✅
Protocol Mappings
(decode as)
Export to CSV / Excel / ✅
XML / CASE / JSON-
LD
Configurable file ✅
output directory
Configurable time zone ✅
(UTC, local or custom)
Geo IP localization ✅
(***)
DNS ✅
Whitelisting (****)
Advanced OS ✅
fingerprinting
Web browser ✅
tracing (4:10 into this
video)
Online ad and tracker ✅
detection
Host coloring support ✅
Command line ✅ (through NetworkMinerCLI)
scripting support
Price Free $ 1200 USD
Buy NetworkMiner
Download
Professional
NetworkMiner (free

edition)

* Fingerprinting of Operating Systems (OS) is performed by using databases


from Satori and p0f
** Identified protocols include: DNS, FTP, HTTP, HTTP2, IRC, Meterpreter, NetBIOS
NameService, NetBios SessionService, Socks, Spotify's Server Protocol, SSH, SSL, TDS
(MS-SQL) and TPKT
*** This product includes GeoLite data created by MaxMind, available
from [Link]
**** Domain names in the DNS tab are checked against the Alexa top 1,000,000 sites

NetworkMiner can extract files, emails and certificates transferred over the network by
parsing a PCAP file or by sniffing traffic directly from the network.
NetworkMiner showing files extracted from sniffed network traffic to disk
NetworkMiner showing thumbnails for images extracted to disk

User credentials (usernames and passwords) for supported protocols are extracted by
NetworkMiner and displayed under the "Credentials" tab. The credentials tab sometimes
also show information that can be used to identify a particular person, such as user
accounts for popular online services like Gmail or Facebook.
Another very useful feature is that the user can search sniffed or stored data for
keywords. NetworkMiner allows the user to insert arbitrary string or byte-patterns that
shall be searched for with the keyword search functionality.

NetworkMiner Professional can be delivered either as an Electronic Software Download


(ESD) or shipped physically on a USB flash drive. The product is exactly the same,
regardless of delivery method. NetworkMiner is a portable application that doesn't
require any installation, which means that the USB version can be run directly from the
USB flash drive. However, we recommend that you copy NetworkMiner to the local hard
drive of your computer in order to achieve maximum performance.

» How To Buy NetworkMiner Professional «

Download NetworkMiner
The latest version of NetworkMiner can be downloaded from:
» [Link] (executable application)
   SHA256 hash:
cf477b651c3bcc70d6f5d50f9bdcb6d8cf2dd85b7018109ff474b9df3c7a0f7e
» [Link] (source code)
   SHA256 hash:
270fbac73c973d1af205f2e96a4e555bf0d4b51f662549000c46f9cd76ccbb8c

For older releases of NetworkMiner (prior to version 2.0), please visit the NetworkMiner
page on SourceForge:
[Link]

However, please note that we no longer release new versions of NetworkMiner on


SourceForge.

Common questions

Powered by AI

As a portable application, NetworkMiner can run directly from a USB flash drive without installation, providing flexibility in various environments. This portability ensures quick deployment for incident response or forensic analysis in field operations. However, running it from a local hard drive is recommended for optimal performance and speed .

NetworkMiner reconstructs network sessions by parsing PCAP files to regenerate and reassemble transmitted files, emails, and certificates. This reconstruction helps analysts understand the flow of data through a network, providing insights into the sequence of communication and the context of interactions .

NetworkMiner is an open source Network Forensic Analysis Tool (NFAT) that acts as a passive network sniffer or packet capturing tool. It can detect operating systems, sessions, hostnames, and open ports without affecting network traffic. NetworkMiner parses PCAP files for offline analysis and can regenerate files and certificates, simplifying network traffic analysis and saving analysts' time. It is widely used by incident response teams and law enforcement, enhancing investigation capabilities .

OS fingerprinting is vital for identifying the operating systems of devices within network traffic, aiding in vulnerability assessment and threat detection. NetworkMiner achieves OS fingerprinting through databases from Satori and p0f, providing robust detection capabilities that enhance network visibility for security analysts .

Supporting IPv6 traffic enables NetworkMiner to capture and analyze modern network transactions, which are increasing as networks transition from IPv4. This capacity ensures comprehensive visibility into potential security incidents occurring over IPv6, facilitating the detection of threats specifically targeting these newer protocols .

NetworkMiner can extract X.509 certificates from SSL encrypted traffic such as HTTPS, SMTPS, IMAPS, POP3S, and FTPS. This capability allows an analyst to assess the encryption layers and decipher critical components without directly decrypting the communication itself .

Geo IP localization enables analysts to determine the geographical source of network traffic, which is critical for identifying suspicious activities originating from specific regions. This feature can help correlate network events with potential threat actors and assess global attack patterns. Moreover, the inclusion of MaxMind's GeoLite data enhances accuracy in pinpointing locations .

NetworkMiner extracts usernames and passwords for supported protocols, displaying them in the 'Credentials' tab. This information can identify user accounts on services like Gmail or Facebook, aiding in associating network activity with specific users. Furthermore, its keyword search functionality allows investigators to search for specific strings or byte-patterns related to credentials .

The command line scripting support in NetworkMiner is beneficial for integrating automated processes into larger incident response or security workflows. It allows for the processing of large volumes of data, scripting repeated tasks, and enabling integration with other tools to create customized forensic or analysis pipelines .

The free edition of NetworkMiner allows for live sniffing, PCAP file parsing, IPv6 support, file extraction from various protocols, and audio extraction capabilities. The professional edition, priced at $1200, includes additional features such as parsing PcapNG files, advanced OS fingerprinting, JA3 and JA3S hash extraction, OSINT lookups, User Defined Port-to-Protocol Mappings, web browser tracing, and command line scripting support .

You might also like