networkminer
Installation
SKILL.md
NetworkMiner
Session-centric network forensics and object extraction from PCAP evidence.
When to use
- You need rapid host/session overview from
.pcap/.pcapngfiles. - You need extracted files, credentials, DNS/HTTP metadata, or transferred objects.
- You need evidence-first triage before deep packet dissection.
- You need to pivot quickly from network traces to investigation artifacts.
Core workflow
- Load PCAP and enumerate hosts, sessions, and protocols.
- Review extracted objects (files, credentials, parameters, certificates).
- Build communication sequence by source/destination and service.
- Export relevant artifacts for corroboration with endpoint evidence.
- Record exact packet/session references for each conclusion.