Skip to content

Autopsy Module that extracts Packet Captures (pcaps) from Data Sources. .

License

Notifications You must be signed in to change notification settings

thePidge/netArchae

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

9 Commits
 
 
 
 
 
 

Repository files navigation

netArchae

###Version 3.1.3 of Autopsy Required This Autopsy Module extracts Packet Captures (pcaps) from Data Sources. It then sorts them under a "PCAPs" tab within "Interesting Files" and allows the extracted pcaps to be parsed by KeywordSearch.

In order to use this module, you must have Autopsy version 3.1.3 installed.

Directions to load and run the module are outlined below:

  1. Run Autopsy
  1. Add Data Source
  2. Navigate to Tools on the Autopsy Menu
  3. Choose Python Plugins
  4. Create a folder with the name of the plugin
  5. Copy netarchae.py into the folder
  6. Close out of the Python Plugins folder
  7. Right click on the Data Source you would like to parse for packet captures
  8. Select Run Ingest Modules
  9. Check the box next to the modules you would like to run
  10. in this case, choose NetArchae (note that you can choose multiple modules)
  11. Once the module has run, provided it yields results, you will see a new "PCAPs" tab under "Interesting Items". You can also see extracted pcaps by generating a report or clicking on the "Ingest Messages" icon.

About

Autopsy Module that extracts Packet Captures (pcaps) from Data Sources. .

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages