Wireshark
Graphical packet analyzer that decodes traffic protocol by protocol.
Wireshark is a graphical packet analyzer that decodes network traffic one protocol at a time, so you see exactly what was sent instead of what a tool claims it sent. It reads frames live off an interface or from a saved capture file and breaks each one down to individual fields. The skill is filtering the flood down to the one conversation you care about. This page covers installing Wireshark, taking a first capture, and the filters you will use every day.
Use it only on systems you own or are authorized to test.
Installing Wireshark
Install Wireshark from your package manager or the official installer. On Linux, add your user to the wireshark group with sudo usermod -aG wireshark $USER so you can capture without root, then log out and back in.
sudo apt install wireshark # Debian, Ubuntu sudo dnf install wireshark # Fedora, RHEL brew install --cask wireshark # macOS
# Windows: run the installer from wireshark.org/download.html # it also installs Npcap, the driver Wireshark uses to capture
Your first capture
In the graphical client you pick an interface and press start. The command-line tshark shares the same engine and is the quickest way to show what a capture looks like; -c 5 stops after five packets.
$ tshark -i eth0 -c 5 1 0.000 10.0.0.5 -> 93.184.16.34 TCP 58122 > 443 [SYN] 2 0.014 93.184.16.34 -> 10.0.0.5 TCP 443 > 58122 [SYN, ACK] 3 0.014 10.0.0.5 -> 93.184.16.34 TCP 58122 > 443 [ACK]
Each line is a packet: time, source, destination, protocol and a summary. In the graphical client these same rows fill the packet list, and clicking one expands every decoded field in the pane below.
Capture filters versus display filters
These are two different tools for two different moments, and mixing them up is the classic beginner mistake. A capture filter decides what is written to disk and must be set before you record. A display filter hides packets you already captured, so you can refine it endlessly without losing data.
| Type | Example | When it applies |
|---|---|---|
| Capture filter | tcp port 443 | Set before recording, writes less to disk |
| Display filter | http.request.method == "POST" | After capture, hides without deleting |
Display filters worth knowing
A handful of display filters cover most of what you look for. Combine them with and, or and not, and right-click any field in a decoded packet to build a filter for its exact value.
ip.addr == 10.0.0.5 # traffic to or from one host http.response.code >= 400 # error responses only tls.handshake.type == 1 # TLS client hellos, with SNI dns.flags.response == 0 # outbound DNS queries
Following a stream and reading TLS
Right-click a packet and choose Follow, and Wireshark stitches the whole TCP, UDP or TLS conversation back together in order. Filter for tls.handshake to watch the versions and cipher suites each side offers: the payload stays encrypted, but the negotiation is in the clear and shows exactly where a failed connection broke.
Capture on a server with tcpdump, then open the pcap in Wireshark on your laptop. The same display filters work in both.
Install
sudo apt install wireshark # Debian, Ubuntu sudo dnf install wireshark # Fedora, RHEL brew install --cask wireshark # macOS # Windows: run the installer from wireshark.org/download.html
Example
# command-line Wireshark: show only TLS client hellos tshark -r capture.pcap -Y "tls.handshake.type == 1" # live capture on one interface, filtered to a host tshark -i eth0 -f "host 10.0.0.5"
Run this against your own lab or systems you have written permission to test — nothing else.