Xplico – Network Forensic Analysis Tool
The goal of Xplico is extract from an internet traffic capture the applications data contained. For example, from a pcap file Xplico extracts each email (POP, IMAP, and SMTP protocols), all HTTP contents, each VoIP call (SIP), FTP, TFTP, and so on. Xplico isn’t a network protocol analyzer. Xplico is an open source Network Forensic Analysis Tool (NFAT). Xplico is released under the GNU General Public License (see License for more details).
Xplico Features
- Protocols supported: HTTP, SIP, IMAP, POP, SMTP, TCP, UDP, IPv6, …;
- Port Independent Protocol Identification (PIPI) for each application protocol;
- Multithreading;
- Output data and information in SQLite database or Mysql database and/or files;
- At each data reassembled by Xplico is associated a XML file that uniquely identifies the flows and the pcap containing the data reassembled;
- Realtime elaboration (depends on the number of flows, the types of protocols and by the performance of computer -RAM, CPU, HD access time, …-);
- TCP reassembly with ACK verification for any packet or soft ACK verification;
- Reverse DNS lookup from DNS packages contained in the inputs files (pcap), not from external DNS server;
- No size limit on data entry or the number of files entrance (the only limit is HD size);
- IPv4 and IPv6 support
- Modularity. Each Xplico component is modular. The input interface, the protocol decoder (Dissector) and the output interface (dispatcer) are all modules
- The ability to easily create any kind of dispatcer with which to organize the data extracted in the most appropriate and useful to you
You can download Xplico 0.5.2 here:
Or read more here.
Tweet
Recent in Forensics:
- Rec Studio 4 – Reverse Engineering Compiler & Decompiler
- CAINE (Computer Aided INvestigative Environment) – Digital Forensics LiveCD
- File Disclosure Browser – Tool To Explore .DS_Store Files
Related Posts:
- NetworkMiner v1.1 Released – Windows Packet Analyzer & Sniffer
- Mobius Forensic Toolkit 0.5.10 – Forensics Framework To Manage Cases & Case Items
- REMnux: A Linux Distribution For Reverse-Engineering Malware
Most Read in Forensics:
- NetworkMiner – Passive Sniffer & Packet Analysis Tool for Windows - 63,835 views
- sslsniff v0.6 Released – SSL MITM Tool - 25,351 views
- Origami – Parse, Analyze & Forge PDF Documents - 23,571 views


Posted in:



Recent Comments