NetworkMiner: Powerful network forensic analysis tool. Extract data & analyze traffic from PCAP files including HTTP, FTP, SMB, and more.
NetworkMiner is a powerful open-source tool specifically designed for network forensics. It excels at extracting valuable information from PCAP files containing captured network traffic, including files, images, emails, and potentially passwords. Beyond analysis of existing data, NetworkMiner can also capture live network traffic directly from a network interface. A key feature is its ability to aggregate detailed information about each IP address within the analyzed traffic into a comprehensive host inventory. This inventory facilitates passive asset discovery and provides a clear overview of all communicating devices on the network. While primarily developed for Windows, NetworkMiner offers compatibility with Linux operating systems, expanding its accessibility.