NETRESEC
Network forensics & traffic analysis
NETRESEC is an independent software vendor specializing in network security monitoring and network forensics. Its tools — led by the widely used NetworkMiner — let incident responders and forensic analysts extract intelligence from captured network traffic and PCAP files, alongside a respected family of free and open-source utilities.

Products
The NETRESEC product line available through Forensic Lab.
Flagship Tools

NetworkMiner
Network forensic analysis tool that parses PCAP files and reconstructs hosts, files, sessions, and credentials.
Learn more
PolarProxy
Transparent TLS-decrypting proxy that intercepts encrypted malware traffic and saves it as decrypted PCAP.
Learn more
FlowCarp
Behaviour-based protocol identification that detects application-layer protocols regardless of port numbers.
Learn more
CapLoader
Handle large PCAP datasets fast — view traffic as TCP/UDP flows, filter, and export to other tools.
Learn moreFree & Open Source Tools

PacketCache
Free Windows service that continuously buffers captured packets in memory for retrospective analysis.
Learn more
RawCap
Tiny command-line sniffer for Windows that needs no drivers and can capture localhost traffic.
Learn more
TrimPCAP
Open-source tool that shrinks PCAP files by over 90% to enable longer traffic retention.
Learn more
findject
Open-source script that detects injected TCP packets and Man-on-the-Side attacks in HTTP sessions.
Learn more
SplitCap
Command-line tool that splits large PCAP files by IP, session, or host for faster filtering.
Learn more