
NetworkMiner
Summary
NetworkMiner analyzes captured network traffic and can sniff live traffic, extracting artifacts such as files, images, emails and passwords from PCAP files. It also builds a host inventory from IP address information to support passive asset discovery and communication overviews. The free edition parses PCAP and ETL files and supports live sniffing on Windows and Linux, but it does not parse PcapNG. NetworkMiner Professional accepts PcapNG, Pcap-over-IP and PacketCache data as well as PCAP and ETL, and exports results to CSV, JSON-LD or XML. Its protocol analysis and VoIP features include file and audio extraction, while OSINT lookups cover hashes, IP addresses, domains and URLs. NetworkMiner does not decrypt HTTPS or other TLS-encrypted sessions. Extracted data stays on the user's device, not in the cloud. The free and open-source code is released under GPLv2. The free plan is 0.00 USD per free; the Single User License is 1300.00 USD per once, valid for three years, and the Corporate License is 6500.00 USD per once.
Who it is for
NetworkMiner suits incident response teams, law enforcement, companies and organizations that need to inspect captured or live network traffic. The free edition is for Windows and Linux users who do not need PcapNG parsing.
What is good
- Extracts files, images, emails and passwords from PCAP files
- Builds a host inventory for passive asset discovery
- Professional exports to CSV, JSON-LD and XML
- Supports live sniffing and multiple capture sources
What to know first
- Does not decrypt HTTPS or other TLS-encrypted sessions
- Free edition does not parse PcapNG
- PCAP files can automatically extract malware
- Professional is not FIPS 140-compliant
Verdict
NetworkMiner combines traffic artifact extraction with host inventory and live sniffing. Check its TLS and FIPS limitations, and use care with PCAP files because they may automatically extract malware.
NetworkMiner plans and pricing
All plansCompared on network packet analyzer software
- Free plan
- Yesnetresec.com
Facts
- Purpose
- NetworkMiner extracts artifacts such as files, images, emails and passwords from captured network traffic in PCAP files and can sniff live network traffic.netresec.com · 1 Oct 2026
- Host inventory
- The software aggregates detailed information about IP addresses into a network host inventory for passive asset discovery and communication overviews.netresec.com · 1 Oct 2026
- Primary users
- Netresec says NetworkMiner has been used by incident response teams, law enforcement, companies and organizations worldwide since its first release in 2007.netresec.com · 1 Oct 2026
- Professional inputs
- NetworkMiner Professional accepts PCAP, PcapNG and ETL capture files, Pcap-over-IP, PacketCache data and live sniffing.netresec.com · 1 Oct 2026
- Professional exports
- NetworkMiner Professional exports data in CSV for Excel, JSON-LD and XML formats.netresec.com · 1 Oct 2026
- Protocol analysis
- Professional supports file extraction from FTP, TFTP, HTTP, HTTP/2, SMB, SMB2, SMTP, POP3, IMAP and LPR protocols.netresec.com · 1 Oct 2026
- VoIP
- Professional supports SIP, RTP, G.711 and G.722, including audio extraction from unencrypted VoIP calls.netresec.com · 1 Oct 2026
- OSINT
- Professional provides OSINT lookups for file hashes, IP addresses, domain names and URLs, plus offline IP-to-country and IP ASN lookups.netresec.com · 1 Oct 2026
- Command line
- NetworkMinerCLI provides command-line scripting support and is available only with a Corporate License.netresec.com · 1 Oct 2026
- TLS handling
- NetworkMiner does not decrypt HTTPS or other TLS-encrypted sessions; it extracts X.509 certificates, and PolarProxy can decrypt traffic and forward it to NetworkMiner.netresec.com · 1 Oct 2026
- Data location
- NetworkMiner stores extracted data locally on the end-user device rather than in the cloud.netresec.com · 1 Oct 2026
- Open source
- The source code is written in 100% managed C# on the Microsoft .NET Framework and is released as GPLv2 free and open source software.netresec.com · 1 Oct 2026
- Safety guidance
- Netresec warns that opening PCAPs can automatically extract malware and recommends Linux or Windows Sandbox to reduce self-infection risk.netresec.com · 1 Oct 2026
- FIPS compliance
- NetworkMiner Professional is not FIPS 140-compliant and requires FIPS enforcement to be disabled on the PC.netresec.com · 1 Oct 2026
Company
- Founded
- 2010netresec.com · 28 Sept 2026
- Headquarters
- Örsundsbro, Swedennetresec.com · 28 Sept 2026
Best NetworkMiner alternatives
See all 12Where it ranks on Everything Xiaomi
Is NetworkMiner yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- netresec.com· checked 1 Oct 2026
- netresec.com· checked 1 Oct 2026
- netresec.com/files/NetworkMiner-Professional_Product· checked 1 Oct 2026
- netresec.com· checked 1 Oct 2026
- netresec.com· checked 1 Oct 2026




