ARKIME
Full packet capture and analysis system (formerly Moloch). Indexes network traffic for search, visualization, and forensic investigation.
INSTALLATION#
# Debian/Ubuntu packages # https://arkime.com/downloads # Or from source git clone https://github.com/arkime/arkime cd arkime && ./easybutton-build.sh # Initialize /opt/arkime/bin/Configure # Initialize Elasticsearch/OpenSearch indexes /opt/arkime/db/db.pl http://localhost:9200 init # Create admin user /opt/arkime/bin/arkime_add_user.sh admin admin password --admin # Start capture systemctl start arkimecapture systemctl start arkimeviewer
CAPTURE#
# Start capture on interface /opt/arkime/bin/capture -c /opt/arkime/etc/config.ini # Config highlights (config.ini): interface=eth0 # Capture interface elasticsearch=http://localhost:9200 # ES endpoint pcapDir=/opt/arkime/raw # PCAP storage maxFileSizeG=2 # Max PCAP file size freeSpaceG=10% # Min free space
WEB INTERFACE#
# Default: http://localhost:8005 # Sessions view — search and analyze captured traffic # SPI View — statistical protocol information # SPI Graph — visual timeline # Connections — network graph # Hunt — full content search # Files — PCAP file management
SEARCH QUERIES#
# IP address ip.src == 10.10.10.5 ip.dst == 10.10.10.5 ip == 10.10.10.5 # Either direction # Port port.src == 80 port.dst == 443 port == 22 # Protocol protocols == tls protocols == http protocols == dns protocols == ssh protocols == smtp # HTTP http.uri == "/admin" http.host == "example.com" http.method == "POST" http.statuscode == 200 http.useragent == *curl* # TLS/SSL tls.ja3 == "HASH" tls.ja3s == "HASH" cert.issuer.cn == "Let's Encrypt" cert.subject.cn == "example.com" # DNS dns.host == "evil.com" dns.status == "NXDOMAIN" # Country country.src == "US" country.dst == "RU" # Bytes bytes > 1000000 # Sessions > 1MB databytes > 5000000 # Data > 5MB # Packets packets > 100 # Tags tags == "known-c2" # Operators ip.src == 10.10.10.5 && port.dst == 443 ip == 10.0.0.0/8 || ip == 192.168.0.0/16 !ip.src == 10.10.10.5
TIPS#
- Full packet capture requires significant storage - Use pcapDir on fast storage (SSD/NVMe) - JA3/JA3S fingerprints identify TLS clients/servers - Hunt feature searches PCAP payload content - Tag sessions for investigation tracking - SPI View shows protocol distribution over time - Elasticsearch/OpenSearch backend enables fast queries - Integrate with Suricata/Zeek for alert correlation - PCAP export for detailed analysis in Wireshark - API available for automation and integration
ARKIME CHEATSHEET ================== Source: https://cheatsheet.johlem.net Full packet capture and analysis system (formerly Moloch). Indexes network traffic for search, visualization, and forensic investigation. INSTALLATION ------------- # Debian/Ubuntu packages # https://arkime.com/downloads # Or from source git clone https://github.com/arkime/arkime cd arkime && ./easybutton-build.sh # Initialize /opt/arkime/bin/Configure # Initialize Elasticsearch/OpenSearch indexes /opt/arkime/db/db.pl http://localhost:9200 init # Create admin user /opt/arkime/bin/arkime_add_user.sh admin admin password --admin # Start capture systemctl start arkimecapture systemctl start arkimeviewer CAPTURE -------- # Start capture on interface /opt/arkime/bin/capture -c /opt/arkime/etc/config.ini # Config highlights (config.ini): interface=eth0 # Capture interface elasticsearch=http://localhost:9200 # ES endpoint pcapDir=/opt/arkime/raw # PCAP storage maxFileSizeG=2 # Max PCAP file size freeSpaceG=10% # Min free space WEB INTERFACE -------------- # Default: http://localhost:8005 # Sessions view — search and analyze captured traffic # SPI View — statistical protocol information # SPI Graph — visual timeline # Connections — network graph # Hunt — full content search # Files — PCAP file management SEARCH QUERIES ---------------- # IP address ip.src == 10.10.10.5 ip.dst == 10.10.10.5 ip == 10.10.10.5 # Either direction # Port port.src == 80 port.dst == 443 port == 22 # Protocol protocols == tls protocols == http protocols == dns protocols == ssh protocols == smtp # HTTP http.uri == "/admin" http.host == "example.com" http.method == "POST" http.statuscode == 200 http.useragent == *curl* # TLS/SSL tls.ja3 == "HASH" tls.ja3s == "HASH" cert.issuer.cn == "Let's Encrypt" cert.subject.cn == "example.com" # DNS dns.host == "evil.com" dns.status == "NXDOMAIN" # Country country.src == "US" country.dst == "RU" # Bytes bytes > 1000000 # Sessions > 1MB databytes > 5000000 # Data > 5MB # Packets packets > 100 # Tags tags == "known-c2" # Operators ip.src == 10.10.10.5 && port.dst == 443 ip == 10.0.0.0/8 || ip == 192.168.0.0/16 !ip.src == 10.10.10.5 TIPS ----- - Full packet capture requires significant storage - Use pcapDir on fast storage (SSD/NVMe) - JA3/JA3S fingerprints identify TLS clients/servers - Hunt feature searches PCAP payload content - Tag sessions for investigation tracking - SPI View shows protocol distribution over time - Elasticsearch/OpenSearch backend enables fast queries - Integrate with Suricata/Zeek for alert correlation - PCAP export for detailed analysis in Wireshark - API available for automation and integration
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.