NetworkMiner is a portable Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc. without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates from PCAP files. The purpose of NetworkMiner is to collect data (such as forensic evidence) about hosts on the network rather than to collect data regarding the traffic on the network.

The interface does not feature any bells and whistles and provides the means for immediate capture of the information. Suffice to select the network card and start the session and data about the hosts is immediately pulled in.

It should show the number of hosts detected and for each of them there are details such as the IP and MAC addresses, the host name, operating system available, TCP ports that are open and the TTL (time to live) value.

The hosts can be organized in various ways so that they are grouped according to the desired relevance.

If all the details have been obtained the screen of the application can be cleared in order to make room for new information. There is no configuration panel to enable setting up the application for other tasks.

NetworkMiner is not difficult to work with, but understanding some of the information it makes available requires some network knowledge. It is not a sniffing tool for network traffic but it can work with offline Pcap data.

Platform: Windows XP/Vista/7/8/8.1/10
License: GPL/Freeware
Author: Website
Size: 1.34MB

SHA256: 87f1a022c22fbcb32852a04265dae6706c7870005d1f037d27f659cf816c5575

