O'Reilly logo

Digital Forensics and Incident Response by Gerard Johansen

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Xplico

Xplico is an open source Network Forensic Analyst Tool (NFAT) that allows an incident response analyst to extract specific application and protocol data contained within a packet capture. Xplico is able to extract information contained within common protocols such as HTTP, SIP, IMAP, IMAP, SMTP, and TCP. Finally, Xplico is able to utilize the DNS packages contained within the packet capture as a reverse DNS lookup, giving detailed information on captured DNS requests. To get Xplico up and running, the following procedure can be utilized:

  1. Xplico is already installed on several well-known forensic platforms, such as DEFT and the CERT-Toolkit. Xplico is also installable on most Linux platforms. To install on Ubuntu-based platforms such ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required