NetworkMiner
NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc.without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates from PCAP files.
NetworkMiner collects data (such as forensic evidence) about hosts on the network rather than to collect data regarding the traffic on the network. The main user interface view is host centric (information grouped per host) rather than packet centric (information showed as a list of packets/frames).
NetworkMiner has, since the first release in 2007, become popular tool among incident response teams as well as law enforcement. NetworkMiner is today used by companies and organizations all over the world.
NetworkMiner (free edition) | NetworkMiner Professional | |
---|---|---|
Live sniffing | ||
Parse PCAP files | ||
Receive Pcap-over-IP | ||
OS Fingerprinting (*) | ||
Port Independent Protocol Identification (PIPI) | ||
Export results to CSV / Excel | ||
Configurable file output directory | ||
Geo IP localization (**) | ||
Host coloring support | ||
Command line scripting support | (through NetworkMinerCLI) | |
PCAP parsing speed (***) | 0.581 MB/s | 0.457 MB/s (GUI version) 0.735 MB/s (command line version) |
Price | Free | € 500 EUR |
Download NetworkMiner (free edition) | Buy NetworkMiner Professional |
* Fingerprinting of Operating Systems (OS) is performed by using databases from Satori and p0f ** This product includes GeoLite data created by MaxMind, available from http://maxmind.com/ *** Measured by loading dump.eth0.1059726000 from Defcon 11 (189MB) on a PC with Intel Core 2 Duo (2,66GHz) and 2GB RAM |
NetworkMiner Professional showing files extracted from sniffed network traffic to disk
NetworkMiner Professional showing thumnails for images extracted to disk
Another very useful feature is that the user can search sniffed or stored data for keywords.
NetworkMiner allows the user to insert arbitrary string or byte-patterns that shall be searched for with the keyword search functionality.
NetworkMiner Professional comes installed on a specially designed USB flash drive. You can run NetworkMiner directly from the USB flash drive since NetworkMiner is a portable application that doesn't require any istallation. We at Netresec do, however, recommend that you copy NetworkMiner to the local hard drive of your computer in order to achieve maximum performance.
» Buy NetworkMiner Professional «
More Information
For more information about NetworkMiner, please see the NetworkMiner Wiki page on SourceForge.There are also several blog posts about NetworkMiner on the NETRESEC Network Security Blog:
- Pcap-over-IP in NetworkMiner
- Network Forensic Analysis of SSL MITM Attacks
- Command-line Network Forensics with NetworkMinerCLI
- NetworkMiner Video Tutorials on the Intertubes
- Webmail Information Leakage
- Analyzing the TCP/IP Weapons School Sample Lab
NetworkMiner_1-1.zip
nb : netresec
Tidak ada komentar:
Posting Komentar