Packet Capture Analysis with Xplico
In this chapter, we’ll look into Xplico, which is an automated Network Forensic Analysis Tool (NFAT). Xplico can be found in Kali Linux; however, I’ve found that within the last few releases (2019–2022), there are issues when trying to run Xplico, possibly due to upgrades within Kali itself.
Although I will explain how to start Xplico in Kali Linux for those who may have the good fortune of running it without issues, we will be using Xplico within a virtual machine running DEFT Linux 8.1, for those of us who may have difficulties running Xplico within Kali itself.
We will be covering the following main topics in this chapter:
- Installing Xplico in Kali Linux
- Installing DEFT Linux 8.1 in VirtualBox
- Downloading sample analysis files
- Starting Xplico in DEFT Linux
- Using Xplico to automatically analyze web, email, and voice traffic