Cheatsheet
Wireshark display filters
Filter expressions to type from memory, grouped by what you are usually asking.
25/25
Addressing
- One host either direction
ip.addr == 192.0.2.10 - As source only
ip.src == 192.0.2.10 - Subnet
ip.addr == 192.0.2.0/24 - Either endpoint in a list
ip.addr in {192.0.2.10 192.0.2.11 192.0.2.12} - MAC address
eth.addr == aa:bb:cc:00:11:22 - Not this address
!ip.addr == 192.0.2.1
Ports & protocols
- Port on either side
tcp.port == 443 - Port range
tcp.port in {80 443 8000-8100} - UDP only
udp && port 53 - DNS queries only
dns.flags.response == 0 - NXDOMAIN answers
dns.flags.rcode == 3 - TLS handshake failures
tls.alert_message - HTTP requests
http.request - HTTP status 500+
http.response.code >= 500
TCP behaviour
- SYNs (connection attempts)
tcp.flags.syn == 1 && tcp.flags.ack == 0 - RSTs
tcp.flags.reset == 1 - Retransmissions
tcp.analysis.retransmission - Zero window / back-pressure
tcp.analysis.zero_window - Handshake duration field
tcp.handshake.time > 0.25 - One conversation
tcp.stream eq 42
Content and size
- Contains a string
frame contains "401 " - Matches a regex (case-insensitive)
http.host matches "(?i)api\." - Bigger than a threshold
frame.len > 1400 - Only the first 30 seconds
frame.time_relative < 30 - A header value exists
http.authorization