July 2017
Beginner to intermediate
324 pages
7h 48m
English
Xplico is an open source Network Forensic Analyst Tool (NFAT) that allows an incident response analyst to extract specific application and protocol data contained within a packet capture. Xplico is able to extract information contained within common protocols such as HTTP, SIP, IMAP, IMAP, SMTP, and TCP. Finally, Xplico is able to utilize the DNS packages contained within the packet capture as a reverse DNS lookup, giving detailed information on captured DNS requests. To get Xplico up and running, the following procedure can be utilized:
Read now
Unlock full access