Xplico is an open source Network Forensic Analyst Tool (NFAT) that allows an incident response analyst to extract specific application and protocol data contained within a packet capture. Xplico is able to extract information contained within common protocols such as HTTP, SIP, IMAP, IMAP, SMTP, and TCP. Finally, Xplico is able to utilize the DNS packages contained within the packet capture as a reverse DNS lookup, giving detailed information on captured DNS requests. To get Xplico up and running, the following procedure can be utilized:

  1. Xplico is already installed on several well-known forensic platforms, such as DEFT and the CERT-Toolkit. Xplico is also installable on most Linux platforms. To install on Ubuntu-based platforms such ...

Get Digital Forensics and Incident Response now with O’Reilly online learning.

O’Reilly members experience live online training, plus books, videos, and digital content from 200+ publishers.