Open Source Network Forensic Analysis Tool (NFAT) 

Twitter E-mail RSS

Xplico 1.2.0

Xplico 1.2.0 is now available.


  • Migration from PHP5 to PHP7
  • CakePHP 2.8
  • nDPI updated
  • IMAP bug fix
  • Bugfix: reported on Security Onion


Xplico 1.1.1

Xplico 1.1.0 is now available.


  • nDPI updated
  • MGCP dissector
  • IMAP bug fixed
  • WhatsApp dissector (it collects only one/two info)
  • bug fixed


Xplico 1.1.0

Xplico 1.1.0 is now available!


  • Performance improved
  • nDPI updated
  • IRC bug fixed
  • HTTP bug fixed
  • VoIP (SIP, RTP) bug fixed
  • FTP bug fixed
  • changed the FaceBook DB tables
  • Null/Loopback dissector
  • Cisco HDLC dissector
  • and RossoAlice WebMail decoding
  • Yahoo messenger, Web and Mobile (Beta version)
  • Dig using file signatures (for unknown flows)

A special thanks to:

… thank you for not using encryption in the [users] communications.


Xplico 1.0.1

Xplico 1.0.1 is now available!


  • nDPI integration
  • performace improved
  • FTP dissector improved
  • Added the prism dissector
  • CLI execution bug fixed
  • PCAP-over-IP SSL encryption
  • IRC dissector improved
  • File reconstruction from Fragmented Payloads improved
  • FaceBook Chat updated
  • FaceBook Message (partial)
  • HTTP without initial packets (packets lost)
  • RTP dissector improved
  • PCAP2WAV, RTP2WAV interface added


Xplico 1.0.0 Released

Xplico 1.0.0 is now available!


  • SQLite dispatcher performance improved
  • added the PPI dissector
  • added the syslog dissector
  • added “Bogus IP length” correction with checksum verification disabled
  • new Facebook Chat dissector for the new Facebook chat protocol
  • SIP dissector improved
  • IMAP dissector improved and bugs fixed
  • DNS dissector PIPI improved
  • Yahoo Webmail bugs fixed
  • Live/Hotmail WebMail Spanish version
  • GeoMap improved
  • PCap-over-IP

Xplico Repository (Ubuntu 11.04 or higher)

To install Xplico in your Ubuntu Server or in your Desktop now you can use the official Xplico repository. With four simple steps you can have Xplico running and updated.

sudo bash -c 'echo "deb $(lsb_release -s -c) main" >> /etc/apt/sources.list'
sudo apt-key adv --keyserver --recv-keys 791C25CE
sudo apt-get update
sudo apt-get install xplico



Xplico 0.7.0: Gmail and language localization

This version introduces improvement on Webmail sniffing/decoding and the language localization.

The Earth seen from Apollo 17 (NASA)Changelog:

  • upgraded the XI to Cakephp 1.3
  • added the ICMPv6 dissector
  • Ethernet dissector improved (for ICMPv6)
  • one of two Xplico’s deadlock is solved
  • fixed the communication bug between xplico and the manipulators
  • SDP dissector bug fixed
  • SIP and TCP dissectors improved
  • WebMail manipulator and all Python3 scripts improved (ready to new webmail entry… see pol 😉 )
  • added pcap file name on CLI report
  • capture modules log improved
  • new GeoIP version: 1.4.8
  • added IPv6 Hop-by-Hop options
  • Xplico and all Manipulators with dual stack (IPv4, IPv6)
  • XI language localization (each fix is ​​well come): Arabic, Chinese, German, English, French, Hindi, Italian, Japanese, Portuguese, Russian, Spanish, Turkish
  • DNS bug fixed
  • added the MDNS dissector
  • added AOL WebMail
  • added Yahoo! WebMail
  • added Yahoo! Mail for Andorid Mobile
  • added Gmail

We thank:

  • briaeros007 (member of the forum) for his test about IPv6 functionality on Xplico’s applications
  • James Fisher, he has found and fixed a bug in the HTTP dissector

Enjoy Xplico!

Web Demo

We are completing the tests on 0.7.0 version. In this release the main features are:

  • Gmail Webmail (HTTP)
  • Yahoo! Mobile Mail (Andorid)
  • AOL WebMail (last version)
  • Language localization

The “WebMail sniffer” component (manipulator and python scripts) were improved.
All this features and others can be  examined and tested with the Web Demo of Xplico.
Any help on Language translation and bug report or suggestions are greatly appreciated.
In the Web Demo all data can be remove by you, in anyway all data (but not the users accounts) are removed every day at 00:00 UTC. More info about Web Demo can be found here.

Xplico 0.6.3: 64Bit

In this release:

  • 32 and 64 bit
  • new decoding manager (DeMa): version 0.3.1
  • mfile manipulator (HTTP file transfer) bug fixes
  • WebMail scripts improved
  • HTTP dissector improved
  • XI: upgraded the javascript libraries

Enjoy !

WebMail decoder… which do you prefer?

We are adding new WebMail decoder to Xplico, but since there are a large number of WebMail on the web, we ask for your advice.

What are the WebMail to add to Xplico?

  • Google Mail: HTTP GMail (30%, 77 Votes)
  • Yahoo! Mobile (18%, 46 Votes)
  • GMX: (Germany) (10%, 25 Votes)
  • Rouncube: (9%, 24 Votes)
  • 163: (China) (9%, 23 Votes)
  • Horde: (9%, 23 Votes)
  • Orange: (France) (7%, 19 Votes)
  • Libero: (Italy) (3%, 8 Votes)
  • Rediff: (India) (2%, 6 Votes)
  • MYNET: (Turkey) (2%, 4 Votes)
  • TTNET: (Turkey) (1%, 3 Votes)

Total Voters: 199

Loading ... Loading ...

You can comment this post to add new webmail (not in the poll). In the comment specify:

  • The service name
  • WebMail URL
  • Nationality

We will add your proposal in the poll.

Xplico 0.6.2: l7-patterns

This version introduces l7-patterns classifier for all flows not decoded, also there is the improvement of the real time acquisition, new features for the XI (Xplico Interface) and many bugs fixes.


  • l7-patterns for all flows/protocols not decoded by xplico
  • Xplico Interface (XI) improved
  • python3 porting of many scripts
  • realtime capture module improved
  • facebook chat realtime view
  • UTC/localtime bug fixes
  • l2tp dissector bug fixes
  • cli and lite dispatchers bug fixes
  • telnet dissector bug fixes
  • trigcap bug fixes
  • new script named session_mng.pyc to facilitate the creation of new case and/or new session from command line

We thank naif for his support and his availability.

The decoding performance are:

  • from command line: 5.9 MB/s
  • from Xplico Interface (XI) with SQLite DB (=> lite dispatcher): 1.76 MB/s
  • from Xplico Interface with MySQL DB (=> ximysql dispatcher): 4.09 MB/s

measured on an Aspire 5633WLMi (Intel Core 2 Duo processor T5500 with 1GB RAM an HD IDE controller) with the pcap (851 MB).

As always: Enjoy !