
Arkime
Arkime is a free open-source packet capture and session search tool used to record, index, and investigate network traffic at scale for security teams.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- Linux
- License
- Open source
- Reviewed
- Last reviewed 10 October 2026
What it is
A system that watches network links passively, parses layers 3 to 7, and stores session records in OpenSearch or Elasticsearch, with full packets kept in standard PCAP format if wanted. It was previously known as Moloch.
What it helps with
- Pivoting from an alert to the exact network sessions behind it
- Pulling raw packets for a session and exporting them as PCAP
- Searching DNS names, HTTP headers, TLS and JA4 fingerprints, and file hashes
- Scaling capture across clustered sensors
Who it's for
Network defenders and incident responders who need searchable history of traffic on networks they run.
Worth knowing
It can run as a metadata-only engine that skips saving packets, which cuts storage needs. The project says clustered deployments scale to hundreds of gigabits per second.
Does it replace an IDS?
No, it sits next to an IDS and SIEM to give the session and packet evidence behind their alerts.
Is there a public demo?
Yes, a demo is linked from arkime.com.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.