Arkime is an open source, large-scale, full packet capturing, indexing, and database system designed to augment existing security infrastructure by storing and indexing network traffic in standard PCAP format. It offers full network visibility, facilitating the swift identification and resolution of security and network issues. Security teams gain access to the necessary network visibility data essential for responding to and investigating incidents to expose the full attack scope. Designed to be deployed across multiple clustered systems, Arkime provides the ability to scale to hundreds of gigabits per second. It allows security analysts to respond, reconstruct, investigate, and confirm information about the threats within your network, enabling appropriate responses quickly and precisely. As an open-source platform, Arkime provides users with the benefits of transparency, cost-effectiveness, flexibility, and community support.
Features
- Security teams gain access to the necessary network visibility data
- Designed to be deployed across multiple clustered systems
- Allows security analysts to respond, reconstruct, investigate and confirm information about the threats
- Provides users with the benefits of transparency, cost-effectiveness, flexibility
- Take the appropriate response quickly and precisely
- Scale to hundreds of gigabits per second