Arkimeet 2026

Amazon IAD28, Herndon, VA

Oct 6, 2026,
9 AM – 5 PM

Arkimeet 2026

Amazon IAD 28, Herndon, VA

Oct 6, 2026,
9 AM – 5 PM

Arkimeet is back! Spend a day with the creators, contributors, and power users behind Arkime.

Join the Arkime community for a day of sharing, learning, and collaboration. Swap war stories with fellow Arkimists, get a first look at brand-new features, and help shape what's next on the roadmap.

Whether you're capturing your first packet or you've spent years hunting threats, there's something here for every experience level — especially if your team runs network security monitoring as part of a "Blue Team."

New to Arkime? It's the open-source, full-packet-capture platform for network security monitoring at scale.

Registration was required and is now closed — see you there if you signed up! Please contact us if you have any questions.


  Join us in the #arkimeet Slack channel in the arkime workspace.  

Agenda

9:00 AM – 5:00 PM EDT

  • 9:00 
    Breakfast
  • 9:30 
    Arkime Keynote
    It has been a while since our last conference, so we have a lot to catch up on. We’ll talk about where we have been, and walk through what has landed over the last few years: the headline features you already know, and the quietly useful ones hiding in a menu you have never clicked. And yes, we’ll talk about AI — not as a feature (yet), but as a tool we are using ourselves. We’ll be honest about where it has actually sped up Arkime development, where it has wasted our time, and the kinds of security issues and bugs it’s finding.
  • 10:30
    Hunting APTs at Domain Zero

    Adversaries, especially APT groups, routinely stand up infrastructure on domains registered days or hours before an operation begins. By the time a domain shows up on a reputation blocklist, the campaign may already be underway. This talk introduces NRD-db, an open-source Docker/Redis pipeline that ingests newly registered domains then feeds that intelligence directly into Arkime’s WISE tagging.

    I’ll cover the architecture, then demo it live: recognizing a newly-registered domain in Arkime sessions and pivoting through existing enrichment data tools to assess it as a potential APT staging point.

    Takeaways: a deployable open-source tool and a practical WISE integration pattern for anyone running network security monitoring or threat hunting with Arkime. Aimed at analysts and engineers from beginner to advanced.

    github.com/StrackVibes/NRD-db

  • 11:00
    Break
  • 11:15
    Hatching Owls
    Building Arkime features from real world investigations.
  • 11:45
    Detecting Everything with JA4+

    In this presentation we will go over, “What is JA4+?”

    And how to use JA4+ to identify:

    • Suspicious/malicious connections through residential proxies and VPNs
    • Bots
    • AI agents and scrapers
    • Exploit tools
    • DDoS tools
    • Malware
    • Devices and software on the network
    • Malicious servers / C2s on the Internet
    • Reverse SSH shells

    We’re basically going to show you how to solve the internet in about 45 minutes.

  • 12:30
    Lunch
  • 13:30
    What Broke: Moving Arkime’s Database to AWS Managed OpenSearch
    We moved Arkime’s database off self-managed Elasticsearch and onto AWS Managed OpenSearch. Most of what went wrong was Arkime assuming the far end of a connection was something it owned. This talk invesitgates three issues, and the merged upstream PRs each one produced.
  • 14:00
    Context 4 Cont3xt

    Manually enriching indicators is slow, repetitive work. This talk covers what Cont3xt is and where it came from, how to actually use it day to day and pair it with Arkime, the integrations it ships with, and its MCP support.

    Takeaways: a look at what Cont3xt is, what it can do for you, and why it deserves a place in your toolkit.

  • 14:30
    The Sessions of Theseus
    A follow-up to my 2023 Kafka talk: my team and I built the PCAP reconstruction pipeline I sketched back then — and learned the hard way that reprocessing PCAPs through Arkime re-creates your sessions and breaks cross-cluster queries. The fix: repack, don’t re-capture. Three production tools — live-saver, packet-signaler, and packet-packer — that deliver long-term PCAP storage with your session identity intact.
  • 15:00
    Break
  • 15:15
    Interactive Demo of the Upcoming Arkime 7 Release
    Arkime 7 is coming, and we can’t wait to show it off. We’ll walk through the changes live — from experimental ClickHouse support as a database and our new tshark integration, down to the reworked Cont3xt settings page layout — but this session is a conversation, not a slide deck. Some of our design decisions are still up in the air, so bring your opinions: the feedback you give us in this room will shape what ships.
  • 16:00
    Arkime 7 CTF
    Let’s see if you were paying attention! We are going to do a quick Arkime CTF with prizes for the top 3.
    Andy & you all
  • 16:30
    Lightning talks
    Let's open the floor to random discussions and start a dialog to discuss which features the community needs most!
    All
  • 17:30
    Happy Hour!
    17:30 – 20:00 at Ornery Beer Company, 2310 Woodland Crossing Dr. Parking in front of Harris Teeter is easiest.

Venue

Amazon IAD28
13200 Woodland Park Rd
Herndon, VA 20171
Room 2.203/2.206

Dulles Airport (IAD) is the closest airport.
Innovation Metro Station is the closest metro stop, about 1.1 miles.

There is a FREE parking garage on site, but you MUST bring your ticket in to be validated. ID will be required and must match the name you used to register

SPEAKERS


Andy Wick

Arkime Wrangler
 

See bio

Elyse Rinne

Software Engineer
 

See bio

Shane Strack

Air Force Warrant Officer
 

See bio

Eoin Miller

Incident Response
 

See bio

John Althouse

Founder, FoxIO
 

See bio

Liam Salusky

Digital Forensics Student
 

See bio

Owen McGill

Dev/Ops Engineer
 

See bio

SPONSORS

Want to be a sponsor?
Email arkime@arkime.com or Slack @elyse or @andywick.

See you there!

Arkime Logo