Autopsy Module that extracts Packet Captures (pcaps) from Data Sources. .
Switch branches/tags
Nothing to show
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Failed to load latest commit information.


###Version 3.1.3 of Autopsy Required This Autopsy Module extracts Packet Captures (pcaps) from Data Sources. It then sorts them under a "PCAPs" tab within "Interesting Files" and allows the extracted pcaps to be parsed by KeywordSearch.

In order to use this module, you must have Autopsy version 3.1.3 installed.

Directions to load and run the module are outlined below:

  1. Run Autopsy
  1. Add Data Source
  2. Navigate to Tools on the Autopsy Menu
  3. Choose Python Plugins
  4. Create a folder with the name of the plugin
  5. Copy into the folder
  6. Close out of the Python Plugins folder
  7. Right click on the Data Source you would like to parse for packet captures
  8. Select Run Ingest Modules
  9. Check the box next to the modules you would like to run
  10. in this case, choose NetArchae (note that you can choose multiple modules)
  11. Once the module has run, provided it yields results, you will see a new "PCAPs" tab under "Interesting Items". You can also see extracted pcaps by generating a report or clicking on the "Ingest Messages" icon.