Observe network activity
Record endpoint, direction, timing, protocol, observed byte and event metadata from an operator-started Windows capture session.
Nioret Systems - Windows evidence
A Windows network activity recorder that preserves observed connection metadata as local, reviewable evidence for investigations and incident follow-up.
AvailableOne-time purchase, no subscription. All 1.x updates are included; future major versions are not promised.

Verified capabilities
The recorder captures Windows TCP/IP activity metadata and attempts local application and process attribution. It does not capture packet payloads or inspect HTTPS/TLS plaintext.
Record endpoint, direction, timing, protocol, observed byte and event metadata from an operator-started Windows capture session.
Review applications, processes, connections, health information, case notes, and tags while evidence remains on the PC.
Create deterministic ZIP evidence exports with a manifest and hashes for review and preservation workflows.
Use cases and limits
Use it to document a bounded troubleshooting session, review application-to-endpoint activity, or preserve connection metadata for later investigation.
Windows requirements and pricing
Capture begins only after an operator action and Windows administrator consent. Evidence defaults to the current Windows account's local app-data folder, and the evidence root can be changed for future sessions.
No subscription. All 1.x updates are included. This offer does not promise future major versions. Protected downloads require an active trial or purchased license.
Trial & Purchase TermsNioret Network Forensic Recorder
Use the Download Center to begin the trial or restore existing access to the protected signed installer.