Network GPL-2.0 Linux, macOS, Windows

Wireshark

Graphical packet analyzer that decodes traffic protocol by protocol.

>_ Official sitewireshark.org Visit

Wireshark is a graphical packet analyzer that decodes network traffic one protocol at a time, so you see exactly what was sent instead of what a tool claims it sent. It reads frames live off an interface or from a saved capture file and breaks each one down to individual fields. The skill is filtering the flood down to the one conversation you care about. This page covers installing Wireshark, taking a first capture, and the filters you will use every day.

Scope

Use it only on systems you own or are authorized to test.

Installing Wireshark

Install Wireshark from your package manager or the official installer. On Linux, add your user to the wireshark group with sudo usermod -aG wireshark $USER so you can capture without root, then log out and back in.

bash
sudo apt install wireshark        # Debian, Ubuntu
sudo dnf install wireshark        # Fedora, RHEL
brew install --cask wireshark     # macOS
bash
# Windows: run the installer from wireshark.org/download.html
# it also installs Npcap, the driver Wireshark uses to capture

Your first capture

In the graphical client you pick an interface and press start. The command-line tshark shares the same engine and is the quickest way to show what a capture looks like; -c 5 stops after five packets.

tshark -i eth0 -c 5
$ tshark -i eth0 -c 5
1  0.000  10.0.0.5 -> 93.184.16.34  TCP  58122 > 443 [SYN]
2  0.014  93.184.16.34 -> 10.0.0.5  TCP  443 > 58122 [SYN, ACK]
3  0.014  10.0.0.5 -> 93.184.16.34  TCP  58122 > 443 [ACK]

Each line is a packet: time, source, destination, protocol and a summary. In the graphical client these same rows fill the packet list, and clicking one expands every decoded field in the pane below.

Capture filters versus display filters

These are two different tools for two different moments, and mixing them up is the classic beginner mistake. A capture filter decides what is written to disk and must be set before you record. A display filter hides packets you already captured, so you can refine it endlessly without losing data.

TypeExampleWhen it applies
Capture filtertcp port 443Set before recording, writes less to disk
Display filterhttp.request.method == "POST"After capture, hides without deleting

Display filters worth knowing

A handful of display filters cover most of what you look for. Combine them with and, or and not, and right-click any field in a decoded packet to build a filter for its exact value.

bash
ip.addr == 10.0.0.5            # traffic to or from one host
http.response.code >= 400      # error responses only
tls.handshake.type == 1        # TLS client hellos, with SNI
dns.flags.response == 0        # outbound DNS queries

Following a stream and reading TLS

Right-click a packet and choose Follow, and Wireshark stitches the whole TCP, UDP or TLS conversation back together in order. Filter for tls.handshake to watch the versions and cipher suites each side offers: the payload stays encrypted, but the negotiation is in the clear and shows exactly where a failed connection broke.

Next step

Capture on a server with tcpdump, then open the pcap in Wireshark on your laptop. The same display filters work in both.

Install

shell
sudo apt install wireshark        # Debian, Ubuntu
sudo dnf install wireshark        # Fedora, RHEL
brew install --cask wireshark     # macOS
# Windows: run the installer from wireshark.org/download.html

Example

shell
# command-line Wireshark: show only TLS client hellos
tshark -r capture.pcap -Y "tls.handshake.type == 1"

# live capture on one interface, filtered to a host
tshark -i eth0 -f "host 10.0.0.5"
Authorized use only

Run this against your own lab or systems you have written permission to test — nothing else.