Arkime
Full packet capture and indexing platform for storing, searching, and inspecting PCAP files across large enterprise networks.
Technical Architecture & Overview
Arkime (formerly Moloch) is an open-source, large-scale full packet capture and indexing system. It captures, indexes, and stores network session data with a web UI for searching and PCAP export, complementing tools like Wireshark for retrospective network forensics at enterprise scale.
Targeted Technical Use Cases
Long-term full packet capture and searchable session indexing for enterprise network forensics.
Evaluation & Trade-offs
Core Strengths
- +Scales to capture and index traffic across multiple high-bandwidth sensors.
- +Web UI provides powerful session search with PCAP export to Wireshark for deep analysis.
- +Integrates with OpenSearch/Elasticsearch for distributed indexing and long-term storage.
Trade-Offs & Limitations
- -Requires significant storage capacity for full packet capture at enterprise scale.
- -Deployment and cluster management require dedicated infrastructure planning.
Defensive Security Application
Retrospective network forensics, long-term traffic storage, and session-level threat hunting.
Frequently Asked Questions
What is Arkime?→
Arkime (formerly Moloch) is an open-source, large-scale full packet capture and indexing system. It captures, indexes, and stores network session data with a web UI for searching and PCAP export, complementing tools like Wireshark for retrospective network forensics at enterprise scale.
What is Arkime used for?→
Long-term full packet capture and searchable session indexing for enterprise network forensics.
What are the strengths of Arkime?→
- +Scales to capture and index traffic across multiple high-bandwidth sensors.
- +Web UI provides powerful session search with PCAP export to Wireshark for deep analysis.
- +Integrates with OpenSearch/Elasticsearch for distributed indexing and long-term storage.
What are the limitations of Arkime?→
- +Requires significant storage capacity for full packet capture at enterprise scale.
- +Deployment and cluster management require dedicated infrastructure planning.
How is Arkime used defensively?→
Retrospective network forensics, long-term traffic storage, and session-level threat hunting.