← All cheat sheets

ARKIME

Plain-text reference · 3 KB. Read it, search it (Ctrl-F) or print it.

Full packet capture and analysis system (formerly Moloch). Indexes
network traffic for search, visualization, and forensic investigation.

INSTALLATION#

# Debian/Ubuntu packages
# https://arkime.com/downloads

# Or from source
git clone https://github.com/arkime/arkime
cd arkime && ./easybutton-build.sh

# Initialize
/opt/arkime/bin/Configure

# Initialize Elasticsearch/OpenSearch indexes
/opt/arkime/db/db.pl http://localhost:9200 init

# Create admin user
/opt/arkime/bin/arkime_add_user.sh admin admin password --admin

# Start capture
systemctl start arkimecapture
systemctl start arkimeviewer

CAPTURE#

# Start capture on interface
/opt/arkime/bin/capture -c /opt/arkime/etc/config.ini

# Config highlights (config.ini):
interface=eth0                              # Capture interface
elasticsearch=http://localhost:9200         # ES endpoint
pcapDir=/opt/arkime/raw                     # PCAP storage
maxFileSizeG=2                              # Max PCAP file size
freeSpaceG=10%                              # Min free space

WEB INTERFACE#

# Default: http://localhost:8005
# Sessions view — search and analyze captured traffic
# SPI View — statistical protocol information
# SPI Graph — visual timeline
# Connections — network graph
# Hunt — full content search
# Files — PCAP file management

SEARCH QUERIES#

# IP address
ip.src == 10.10.10.5
ip.dst == 10.10.10.5
ip == 10.10.10.5                            # Either direction

# Port
port.src == 80
port.dst == 443
port == 22

# Protocol
protocols == tls
protocols == http
protocols == dns
protocols == ssh
protocols == smtp

# HTTP
http.uri == "/admin"
http.host == "example.com"
http.method == "POST"
http.statuscode == 200
http.useragent == *curl*

# TLS/SSL
tls.ja3 == "HASH"
tls.ja3s == "HASH"
cert.issuer.cn == "Let's Encrypt"
cert.subject.cn == "example.com"

# DNS
dns.host == "evil.com"
dns.status == "NXDOMAIN"

# Country
country.src == "US"
country.dst == "RU"

# Bytes
bytes > 1000000                             # Sessions > 1MB
databytes > 5000000                         # Data > 5MB

# Packets
packets > 100

# Tags
tags == "known-c2"

# Operators
ip.src == 10.10.10.5 && port.dst == 443
ip == 10.0.0.0/8 || ip == 192.168.0.0/16
!ip.src == 10.10.10.5

TIPS#

  - Full packet capture requires significant storage
  - Use pcapDir on fast storage (SSD/NVMe)
  - JA3/JA3S fingerprints identify TLS clients/servers
  - Hunt feature searches PCAP payload content
  - Tag sessions for investigation tracking
  - SPI View shows protocol distribution over time
  - Elasticsearch/OpenSearch backend enables fast queries
  - Integrate with Suricata/Zeek for alert correlation
  - PCAP export for detailed analysis in Wireshark
  - API available for automation and integration

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.