NetworkMiner 3.2 Released
NetworkMiner 3.2 parses RADIUS authentication data and extracts more details from the OT/ICS protocols UMAS and IEC-104. The release also improves several existing protocol parsers and fixes file-reassembly issues, helping analysts extract more information from captured network traffic.
OT Protocol Support
NetworkMiner parses many OT/SCADA/ICS communication protocols, such as CIP, COTP, EtherNet/IP, IEC 60870-5-104, Modbus/TCP and UMAS. The parsers for UMAS and IEC-104 have been updated in this release.
The parser for Schneider Electric’s proprietary UMAS protocol in NetworkMiner has been improved. NetworkMiner can now extract data from UMAS commands “Read Physical Address” and “Write Physical Address”. This addition enables analysts to determine not only if data stored in memory of a Schneider Modicon PLC has been modified, but also what changed. This visibility is particularly valuable when performing forensic analysis of OT network traffic after an incident.
Image: Data 0x43 written to address 0x0001FF4E on a Modicon M221 PLC
NetworkMiner can parse most commands defined by the IEC 60870-5-104 protocol, which is used for monitoring and controlling systems in European and Asian power grids.
In this release we’ve added support for IEC-104 command ID 60 (C_RC_TA_1) “Regulating step command with time tag CP56Time2a”, which is used to increase or decrease a data-point by one.
Image: Data-point at IOA 16 decremented using IEC-104 command ID 60
RADIUS
NetworkMiner now includes a parser for the authentication and authorization protocol RADIUS. The parser extracts usernames, passwords (encrypted or hashed), IP addresses, messages and various RADIUS-specific identifiers.
Image: Usernames and password related attributes extracted from RADIUS traffic
Image: Parameters extracted from RADIUS packets
RADIUS traffic for the screenshots above comes from Wireshark’s Sample Captures (radius_localhost.pcap) and Johannes Weber’s Ultimate PCAP.
JA4 Download in NetworkMiner Professional
Many users of NetworkMiner Professional have received an error message saying “JA4 database download failed”.
This error message is displayed when NetworkMiner Professional tries to download a JA4 database from FoxIO’s website ja4db.com. After consulting FoxIO in 2024, we implemented a solution that automatically retrieved the JA4 database and checked for updates every 30 days.
This database is unfortunately not available for download anymore, which caused users to see “JA4 database download failed” messages. We apologize for any inconvenience this may have caused.
Version 3.2 no longer attempts to download this database.
Bug Fixes and Other Improvements
NetworkMiner 3.2 includes fixes for several bugs reported by Jeliazko Zlatev, which relate to how files are extracted from PCAP data (thank you Jeliazko!). We have also improved parsers for protocols like HTTP, SIP and DNS to extract even more data from the analyzed network traffic to the various tabs on the user interface.
Upgrading to Version 3.2
Users who have purchased NetworkMiner Professional can download version 3.2 from our customer portal, or use the “Check for Updates” feature from NetworkMiner’s Help menu. Users who prefer to use the free and open source version can grab the latest release of NetworkMiner from the official NetworkMiner page.
Posted by Erik Hjelmvik on Wednesday, 07 October 2026 11:30:00 (UTC/GMT)
Tags: #NetworkMiner #UMAS #IEC-104 #ICS #JA4