Summary
In this chapter, we learned how to use Xplico in both Kali Linux and DEFT Linux, which we installed separately in VirtualBox. DEFT can be a great substitute for those who may have encountered issues when installing Xplico in Kali, and it also offers many other tools that you can explore if you so wish. We learned that a new case and session must be created for each packet capture (.pcap
) file analysis, and that Xplico does automatic decoding and analysis of .pcap
files to reveal artifacts that are useful to our DFIR investigations. Lastly, we learned how to use Xplico to find useful artifacts such as visited websites, viewed and downloaded images, emails, and VoIP conversations. I hope you enjoyed using this automated tool. We will next look at other NFAT tools in our last chapter. See you in the next chapter.