NetworkMiner from Netresec is a forensic tool for network analysis (NFAT) designed for Windows. (but it also works on Linux / Mac OS X / FreeBSD).
NetworkMiner can be used as a passive sniffing tool on the network to identify operating systems, sessions, host names, open ports, etc., without loading the network.
NetworkMiner collects data about computers on the network and not data regarding the traffic that exists on the network. You still support passively the OS fingerprinting feature via the databases from Satori and p0f, and the WiFi sniffing feature via AirPcap.
The NetworkMiner can extract files and certificates that are transferred over the network from the analysis of a PCAP file. This is a feature that can be used for extracting and storing media files (such as audio files or video files or which pages you visit) that exist on a network. Supported protocols for file extraction are FTP, TFTP, HTTP, SMB and SMTP.
The user certificates (usernames and passwords) for the supported protocols appear on the “Credentials” tab. The credentials tab sometimes also shows information that can be used to identify a specific person, such as user accounts for popular online services like Gmail or Facebook.
There is also a commercial version of NetworkMiner. The commercial version is called NetworkMiner Professional and includes additional features such as:
- Independent port identification protocol (PIPI)
- Export results to CSV / Excel
- Editable directory output file
- Geo IP detection
- Support for computer colorization
- Command line support scripting
- Portable USB application
NetworkMiner is a forensic tool that became popular since its first release in 2007 and is used today by companies and organizations worldwide.
https://www.netresec.com/?page=Νetworkminer
Download ΝetworkMiner (free edition)
Dimitris Moutsikas, Konstantinos Samiotis Wikibooks
