Xplico extracts vital information from a pcap file for forensic analysis, Xplico can extract email (POP, IMAP, and SMTP protocols), all HTTP contents, each VoIP call (SIP), and so on. Xplico is an enhanced open source Network Forensic Analysis Tool (NFAT).
Some of the Xplico features include:

• Protocols supported: HTTP, SIP, IMAP, POP, SMTP, TCP, UDP, IPv6
• Port Independent Protocol Identification (PIPI) for each application protocol
• Multi-threading
• Output data and information in SQLite database or Mysql database and/or files
• At each data reassembled by Xplico is associated a XML file that uniquely identifies the flows and the pcap containing the data reassembled
• Real-time elaboration (depends on the number of flows, the types of protocols and by the performance of computer -RAM, CPU, HD access time, …-)
• TCP reassembly with ACK verification for any packet or soft ACK verification
• Reverse DNS lookup from DNS packages contained in the inputs files (pcap), not from external DNS server
• No size limit on data entry or the number of files entrance (the only limit is HD size)

Xplico can be downloaded from here.

Xplico package for Ubuntu 9.04. is available here.

Share and Enjoy:
  • Print
  • Digg
  • del.icio.us
  • Facebook
  • Google Bookmarks
  • DotNetKicks
  • email
  • FriendFeed
  • LinkedIn
  • PDF
  • Twitter
  • Share/Bookmark

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

2 Comments to “Xplico Version 0.5.2 Network Forensic Analysis Tool”

  1. AlexAxe says:

    Hi, Amazing! Not clear for me, how offen you updating your bharath.bitupdate.com.
    Thank you

  2. AlexAxe says:

    Greatings, Super post, Need to mark it on Digg

Leave a Reply

You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>