XPLICO
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Xplico is a Network Forensic Analysis Tool (NFAT) that extracts application-level data from network traffic captures. It reconstructs emails, HTTP content, VoIP calls, and other protocols from pcap files.
LAUNCHING#
# Start Xplico services /etc/init.d/xplico start # Start Xplico /etc/init.d/xplico stop # Stop Xplico /etc/init.d/xplico restart # Restart Xplico # Access web interface # Default: http://localhost:9876 # Login: xplico / xplico (default credentials)
WEB INTERFACE#
# 1. Create a new Case # 2. Create a new Session within the Case # 3. Upload pcap file or set live capture # 4. Wait for decoding to complete # 5. Browse extracted data by protocol
CLI USAGE#
xplico -m pcap -f <capture.pcap> # Process pcap file (CLI) xplico -m rltm -i <interface> # Live capture mode
SUPPORTED PROTOCOLS#
# Email: # - SMTP (sent emails) # - POP3 (received emails) # - IMAP (received emails) # - Webmail (via HTTP) # Web: # - HTTP (pages, files, images) # - HTTPS (if SSL keys available) # - HTTP file downloads # Chat & Messaging: # - MSN Messenger # - IRC # - Facebook chat (via HTTP) # - WhatsApp (partial) # VoIP: # - SIP (call metadata) # - RTP (audio streams) # - Reconstructed audio files # File Transfer: # - FTP (files and commands) # - TFTP (files) # DNS: # - DNS queries and responses # - DNS mapping # Other: # - Telnet sessions # - NNTP (news) # - Syslog messages # - IRC channels
CASE MANAGEMENT#
# Cases organize investigations # Each case can have multiple sessions # Sessions contain pcap data and extracted artifacts # Case → Session → Upload pcap → Decoded data
EXTRACTED DATA VIEWS#
# Web - Reconstructed web pages and downloads # Mail - Emails with attachments # VoIP - Reconstructed phone calls (audio) # Chat - Instant messaging conversations # Files - Transferred files (FTP, HTTP) # Images - Extracted images from web traffic # Videos - Extracted video content # DNS - DNS resolution history # Undecoded - Unrecognized protocol data
CONFIGURATION#
# Config file: /opt/xplico/cfg/xplico_install_scripts.cfg # Web interface config: /opt/xplico/xi/app/Config/ # Key settings: # - Database configuration # - Storage paths # - Protocol decoders # - User management
PCAP SOURCES#
# Import from common tools: # - Wireshark captures (.pcap, .pcapng) # - tcpdump captures # - tshark output # - Any libpcap format
EXAMPLES#
# Process a Wireshark capture xplico -m pcap -f /tmp/capture.pcap # Live capture on interface xplico -m rltm -i eth0 # Web interface workflow: # 1. Login → New Case "Investigation 2024" # 2. New Session "Network Capture 1" # 3. Upload → select capture.pcap # 4. Wait for "Decoding complete" # 5. Browse Web/Mail/VoIP tabs
NOTES#
- Web-based interface on port 9876 - Default credentials: xplico/xplico (change immediately) - Supports pcap and pcapng formats - Can handle very large capture files - Used in digital forensics and incident response - Does not decrypt encrypted traffic without keys - Can reconstruct complete web pages - VoIP reconstruction creates playable audio files - Multi-user support for team investigations