Digital forensics EU-developed

NetworkMiner

Parses PCAP traffic to reconstruct transferred files, credentials and host context for network forensic investigation and incident response.

By NETRESEC AB · Sweden

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Digital forensics
Developer or maintainer
NETRESEC AB
Recorded country
Sweden
Product model
Open core
Deployment
Desktop/CLI
Software license
Mixed: GPL-2.0 free edition; commercial Professional license (full terms not publicly verified)
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Netresec identifies itself as the developer of network forensic software and lists a Swedish legal address; founder Erik Hjelmvik identifies himself as NetworkMiner creator.

Reported capabilities

  • PCAP-based artifact reconstruction
  • Passive host inventory and live capture
  • Free GPL edition plus paid Professional features

Scope and limits

The free edition is GPLv2 and runs locally; paid Professional adds PCAPNG support, enhanced identification and other features under separate commercial licensing. The public product matrix and specifications do not publish full Professional contract terms. Do not treat Professional code as GPL because the free edition is GPL.

Inspect the research evidence 6 source observations
  1. identity / capabilities / deployment

    Vendor calls NetworkMiner an open-source network-forensics tool for local Windows/Linux use, reconstructing files, emails and credentials from PCAPs; its edition matrix separates free and Professional functions.

    Read source
  2. license

    Vendor explicitly applies GNU General Public License version 2 to the free source code and links the full GPLv2 text; the linked text was inspected. This declaration does not cover Professional-only features.

    Read source
  3. license

    The full GNU General Public License version 2 text gives copy, modify and distribution rights subject to its stated conditions; vendor applies it to free NetworkMiner source.

    Read source
  4. origin / country

    NETRESEC AB says it develops software for traffic capture/PCAP analysis and lists its Swedish registered address in Örsundsbro.

    Read source
  5. maintenance

    The vendor published NetworkMiner 3.2 on 7 October 2026 with parser and file-reassembly fixes; the source and free download are linked from its official product page.

    Read source
  6. license

    Vendor specifications distinguish paid named-user and corporate Professional licenses and update entitlements; full commercial end-user terms were not publicly verified.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.

Put the tool in context.

Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.

A digital forensics triage and evidence workflow