NetworkMiner for Network Forensics (Hacking Illustrated Series InfoSec Tutorial Videos)
NetworkMiner for Network Forensics
NetworkMiner is a cool little sniffer app by Erik Hjelmvik. Described as a
Network Forensic Analysis Tool (NFAT), it allows you to parse libpcap files or
to do a live capture of the network and find out various things passively. The
main uses I like it for are file reconstruction of FTP, SMB, HTTP and TFTP
streams as well as passive OS fingerprinting, but it can do a lot more.
NetworkMinor uses the Satori, p0f and Ettercap OS fingerprints, and can be run
from a thumb drive without having to install it. It's designed to run under
Windows, but you can also use it under Linux with Wine.
If the embedded video below does not show RIGHT click here to save the file to your hard drive.
Printable version of this article