Skip to content
This repository has been archived by the owner on Apr 16, 2021. It is now read-only.
Doug Burks edited this page Feb 18, 2017 · 15 revisions

What is Xplico?

From http://www.xplico.org/about:

The goal of Xplico is extract from an internet traffic capture the applications data contained. For example, from a pcap file Xplico extracts each email (POP, IMAP, and SMTP protocols), all HTTP contents, each VoIP call (SIP), FTP, TFTP, and so on. Xplico isn’t a network protocol analyzer. Xplico is an open source Network Forensic Analysis Tool (NFAT).

How do I enable Xplico in Security Onion?

Xplico is enabled automatically if you choose Evaluation Mode. Production Mode disables Xplico. This is controlled in /etc/nsm/securityonion.conf.

How do I log into Xplico?

From http://wiki.xplico.org/doku.php?id=interface:

The default username and password are:
username: xplico
password: xplico

The default admin username and password are:
username: admin
password: xplico

Where do I go for more information about Xplico?

For more information, please see:
http://www.xplico.org/

Clone this wiki locally