Forensic Software & Applications
Explore supported forensic software tools, usage guides, tips & tricks, and direct download links.
Arkime
Arkime Project / AOL (Open Source) • Linux (server)
Large-scale full packet capture and search system for recording and indexing all network traffic.
NetworkMiner
Netresec (Open Source Edition) • Windows / Linux
A passive Network Forensic Analysis Tool (NFAT) for extracting files, credentials, and sessions from network traffic captures.
PcapXray
Srinivas (Open Source) • Windows / Linux / macOS (Python)
A PCAP analysis tool that visualizes network traffic as an interactive graph/map.
Snort
Cisco (Open Source) • Linux / Windows
Open-source, signature-based network intrusion detection and prevention system (IDS/IPS).
Suricata
Open Information Security Foundation (Open Source) • Linux / Windows / macOS
A next-generation IDS/IPS and network security monitoring engine with full multi-threading support.
Wireshark
Wireshark Foundation (Open Source) • Windows / Linux / macOS
The world's most widely used open-source network protocol analyzer for capturing and deeply inspecting packets.
Zeek
Zeek Project (Open Source) • Linux / FreeBSD / macOS
Open-source network security monitoring framework that turns raw traffic into structured, easy-to-analyze event logs.