Digital forensics EU-developed

CapLoader

Indexes large PCAP collections, identifies network protocols, filters suspicious flows and exports selected packets for deeper forensic analysis.

By NETRESEC AB · Sweden

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Digital forensics
Developer or maintainer
NETRESEC AB
Recorded country
Sweden
Product model
Commercial
Deployment
Desktop/CLI
Software license
Commercial license; full terms not publicly verified
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Netresec says it develops its network forensic products in Sweden, and its official CapLoader page identifies this product as one of those tools.

Reported capabilities

  • Large-PCAP flow indexing and filtering
  • Protocol identification and suspicious-flow alerts
  • Packet export and carving from memory or disk images

Scope and limits

CapLoader is a separate Windows desktop product with a 30-day restricted trial and commercial licenses; it is not the GPL NetworkMiner edition. The vendor publishes license options and feature limits, but not the complete current end-user contract. .NET Framework 4.8 is required.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    Official CapLoader page identifies a Windows application for indexing/filtering large PCAP/PcapNG collections and exporting flows to analyzers; it documents protocol identification, packet carving and .NET requirement.

    Read source
  2. license

    Vendor matrix distinguishes 30-day restricted trial from paid Professional edition and publishes price and feature differences; no open-source grant is made.

    Read source
  3. country / origin

    Netresec says it develops and sells network-forensic software and lists its Swedish address, supporting the Swedish product lead.

    Read source
  4. license

    Vendor PDF lists paid single-user and corporate licenses, three-year versus perpetual validity, and electronic delivery. It is a specification sheet, not a complete EULA.

    Read source
  5. maintenance

    Official CapLoader change log lists version 2.1 dated 27 May 2026 with TLS fingerprint reassembly improvements.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.

A digital forensics triage and evidence workflow