Skip to content
Back to skills

Implementing Network Traffic Analysis With Arkime

ASecurity

Queries Arkime (formerly Moloch) full packet capture via its API to search sessions,

  • 67 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 4, 2026
securitypythonbashexpresstestingapisecurity

Works with

  • api

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 4 files and shows the line behind each finding

Scanned September 4, 2026

npx -y skills add costrict-plugins-repo/mukul975-anthropic-cybersecurity-skills-cybersecurity-skills --skill implementing-network-traffic-analysis-with-arkime --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Implementing Network Traffic Analysis With Arkime?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Implementing Network Traffic Analysis With Arkime
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/costrict-plugins-repo-implementing-network-traffic-analysis-with-arkime/badge)](https://www.skillsdirectory.com/skills/costrict-plugins-repo-implementing-network-traffic-analysis-with-arkime)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: implementing-network-traffic-analysis-with-arkime
description: Queries Arkime (formerly Moloch) full packet capture via its API to search sessions,
  download PCAPs, detect C2 beaconing through connection interval/jitter stats,
  spot DNS tunneling via query-length analysis, and flag known-bad TLS certificate
  issuers, using the bundled scripts/agent.py. Use when investigating suspicious
  network flows or doing full-packet-capture forensics against an Arkime deployment.
domain: cybersecurity
subdomain: network-security
tags:
- network-security
- arkime
- full-packet-capture
- nta
- pcap-analysis
- network-forensics
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.IR-01
- DE.CM-01
- ID.AM-03
- PR.DS-02
mitre_attack:
- T1046
- T1040
- T1557
- T1071
- T1095
---


# Implementing Network Traffic Analysis with Arkime


## When to Use

- When deploying or configuring implementing network traffic analysis with arkime capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation

## Prerequisites

- Familiarity with network security concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities

## Instructions

1. Install dependencies: `pip install requests`
2. Configure Arkime viewer URL and credentials.
3. Run the agent to query Arkime sessions and analyze traffic:
   - Search sessions by IP, port, protocol, or expression
   - Download PCAP data for forensic analysis
   - Detect C2 beaconing via connection interval analysis
   - Identify DNS tunneling through query length statistics
   - Flag connections to known-bad TLS certificate issuers

```bash
python scripts/agent.py --arkime-url https://arkime.local:8005 --user admin --password secret --output arkime_report.json
```

## Examples

### Beaconing Detection
```
Source: 10.1.2.50 -> 185.220.101.34:443
Sessions: 288 over 24 hours
Avg interval: 300s, Jitter: 4.2%
Verdict: HIGH confidence C2 beaconing (jitter < 5%)
```

Files in this skill

  • LICENSE11 KB
  • SKILL.md2.2 KB
  • references/api-reference.md2 KB
  • scripts/agent.py8.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…