← All cheat sheets

XPLICO

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Xplico is a Network Forensic Analysis Tool (NFAT) that extracts
application-level data from network traffic captures. It reconstructs
emails, HTTP content, VoIP calls, and other protocols from pcap files.

LAUNCHING#

# Start Xplico services
/etc/init.d/xplico start        # Start Xplico
/etc/init.d/xplico stop         # Stop Xplico
/etc/init.d/xplico restart      # Restart Xplico

# Access web interface
# Default: http://localhost:9876
# Login: xplico / xplico (default credentials)

WEB INTERFACE#

# 1. Create a new Case
# 2. Create a new Session within the Case
# 3. Upload pcap file or set live capture
# 4. Wait for decoding to complete
# 5. Browse extracted data by protocol

CLI USAGE#

xplico -m pcap -f <capture.pcap> # Process pcap file (CLI)
xplico -m rltm -i <interface>    # Live capture mode

SUPPORTED PROTOCOLS#

# Email:
# - SMTP (sent emails)
# - POP3 (received emails)
# - IMAP (received emails)
# - Webmail (via HTTP)

# Web:
# - HTTP (pages, files, images)
# - HTTPS (if SSL keys available)
# - HTTP file downloads

# Chat & Messaging:
# - MSN Messenger
# - IRC
# - Facebook chat (via HTTP)
# - WhatsApp (partial)

# VoIP:
# - SIP (call metadata)
# - RTP (audio streams)
# - Reconstructed audio files

# File Transfer:
# - FTP (files and commands)
# - TFTP (files)

# DNS:
# - DNS queries and responses
# - DNS mapping

# Other:
# - Telnet sessions
# - NNTP (news)
# - Syslog messages
# - IRC channels

CASE MANAGEMENT#

# Cases organize investigations
# Each case can have multiple sessions
# Sessions contain pcap data and extracted artifacts

# Case → Session → Upload pcap → Decoded data

EXTRACTED DATA VIEWS#

# Web     - Reconstructed web pages and downloads
# Mail    - Emails with attachments
# VoIP    - Reconstructed phone calls (audio)
# Chat    - Instant messaging conversations
# Files   - Transferred files (FTP, HTTP)
# Images  - Extracted images from web traffic
# Videos  - Extracted video content
# DNS     - DNS resolution history
# Undecoded - Unrecognized protocol data

CONFIGURATION#

# Config file: /opt/xplico/cfg/xplico_install_scripts.cfg
# Web interface config: /opt/xplico/xi/app/Config/

# Key settings:
# - Database configuration
# - Storage paths
# - Protocol decoders
# - User management

PCAP SOURCES#

# Import from common tools:
# - Wireshark captures (.pcap, .pcapng)
# - tcpdump captures
# - tshark output
# - Any libpcap format

EXAMPLES#

# Process a Wireshark capture
xplico -m pcap -f /tmp/capture.pcap

# Live capture on interface
xplico -m rltm -i eth0

# Web interface workflow:
# 1. Login → New Case "Investigation 2024"
# 2. New Session "Network Capture 1"
# 3. Upload → select capture.pcap
# 4. Wait for "Decoding complete"
# 5. Browse Web/Mail/VoIP tabs

NOTES#

- Web-based interface on port 9876
- Default credentials: xplico/xplico (change immediately)
- Supports pcap and pcapng formats
- Can handle very large capture files
- Used in digital forensics and incident response
- Does not decrypt encrypted traffic without keys
- Can reconstruct complete web pages
- VoIP reconstruction creates playable audio files
- Multi-user support for team investigations