Digital forensics EU-developed
NetworkMiner
Parses PCAP traffic to reconstruct transferred files, credentials and host context for network forensic investigation and incident response.
By NETRESEC AB · Sweden
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts- Response workflow
- Digital forensics
- Developer or maintainer
- NETRESEC AB
- Recorded country
- Sweden
- Product model
- Open core
- Deployment
- Desktop/CLI
- Software license
- Mixed: GPL-2.0 free edition; commercial Professional license (full terms not publicly verified)
- Upstream status
- Active
- Evidence class
- EU-developed
What the sources establish
Origin noteNetresec identifies itself as the developer of network forensic software and lists a Swedish legal address; founder Erik Hjelmvik identifies himself as NetworkMiner creator.
Reported capabilities
- PCAP-based artifact reconstruction
- Passive host inventory and live capture
- Free GPL edition plus paid Professional features
Scope and limits
The free edition is GPLv2 and runs locally; paid Professional adds PCAPNG support, enhanced identification and other features under separate commercial licensing. The public product matrix and specifications do not publish full Professional contract terms. Do not treat Professional code as GPL because the free edition is GPL.
Inspect the research evidence 6 source observations
identity / capabilities / deployment
Vendor calls NetworkMiner an open-source network-forensics tool for local Windows/Linux use, reconstructing files, emails and credentials from PCAPs; its edition matrix separates free and Professional functions.
Read sourcelicense
Vendor explicitly applies GNU General Public License version 2 to the free source code and links the full GPLv2 text; the linked text was inspected. This declaration does not cover Professional-only features.
Read sourcelicense
The full GNU General Public License version 2 text gives copy, modify and distribution rights subject to its stated conditions; vendor applies it to free NetworkMiner source.
Read sourceorigin / country
NETRESEC AB says it develops software for traffic capture/PCAP analysis and lists its Swedish registered address in Örsundsbro.
Read sourcemaintenance
The vendor published NetworkMiner 3.2 on 7 October 2026 with parser and file-reassembly fixes; the source and free download are linked from its official product page.
Read sourcelicense
Vendor specifications distinguish paid named-user and corporate Professional licenses and update entitlements; full commercial end-user terms were not publicly verified.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Plan targeted evidence collection, check acquisition gaps and produce a traceable timeline. Source-linked guidance for Acquire, Dissect and DFIR ORC.
A digital forensics triage and evidence workflow