-
Book Overview & Buying
-
Table Of Contents
Digital Forensics with Kali Linux
By :
Whether using Kali Linux or DEFT Linux, for this chapter we will be using publicly-available, sample packet capture (.pcap) files that can be downloaded at http://wiki.xplico.org/doku.php?id=pcap:pcap.
The files needed are:
DNSMMSWebmail: Hotmail/LiveHTTP (web)SIP example 1We will also require an SMTP sample file available from the Wireshark sample captures page at https://wiki.wireshark.org/SampleCaptures.
In this exercise, we upload the HTTP (web) (xplico.org_sample_capture_web_must_use_xplico_nc.cfg.pcap) sample packet capture file.
For this HTTP analysis, we use Xplico to search for artifacts associated with the HTTP protocol such as URLs, images from websites, and possible browser-related activities.
Once Xplico has been started, log in using the following credentials:
Username: xplicoPassword: xplicoWe then choose New Case from the menu on the left and select the Uploading PCAP capture file/s button as we will be uploading...