Skip to main content

Arkime

Full packet capture and indexing platform for storing, searching, and inspecting PCAP files across large enterprise networks.

Technical Architecture & Overview

Arkime (formerly Moloch) is an open-source, large-scale full packet capture and indexing system. It captures, indexes, and stores network session data with a web UI for searching and PCAP export, complementing tools like Wireshark for retrospective network forensics at enterprise scale.

Targeted Technical Use Cases

Long-term full packet capture and searchable session indexing for enterprise network forensics.

Evaluation & Trade-offs

Core Strengths

  • +Scales to capture and index traffic across multiple high-bandwidth sensors.
  • +Web UI provides powerful session search with PCAP export to Wireshark for deep analysis.
  • +Integrates with OpenSearch/Elasticsearch for distributed indexing and long-term storage.

Trade-Offs & Limitations

  • -Requires significant storage capacity for full packet capture at enterprise scale.
  • -Deployment and cluster management require dedicated infrastructure planning.

Defensive Security Application

Retrospective network forensics, long-term traffic storage, and session-level threat hunting.

Frequently Asked Questions

What is Arkime?

Arkime (formerly Moloch) is an open-source, large-scale full packet capture and indexing system. It captures, indexes, and stores network session data with a web UI for searching and PCAP export, complementing tools like Wireshark for retrospective network forensics at enterprise scale.

What is Arkime used for?

Long-term full packet capture and searchable session indexing for enterprise network forensics.

What are the strengths of Arkime?
  • +Scales to capture and index traffic across multiple high-bandwidth sensors.
  • +Web UI provides powerful session search with PCAP export to Wireshark for deep analysis.
  • +Integrates with OpenSearch/Elasticsearch for distributed indexing and long-term storage.
What are the limitations of Arkime?
  • +Requires significant storage capacity for full packet capture at enterprise scale.
  • +Deployment and cluster management require dedicated infrastructure planning.
How is Arkime used defensively?

Retrospective network forensics, long-term traffic storage, and session-level threat hunting.