Skip to content

Comparison · neutral framing

wireshark vs tcpdump

Both read the same capture format. One is an analysis environment; the other is a capture utility that fits on a server.

Wiresharktcpdumprevised 16 Jan 2026

Attributes

Values describe documented behaviour. Anything workload- or hardware-dependent is written as a practice, not a number.

Interface

  • Graphical analysis

    wireshark
    Documented
    tcpdump
    Not a feature
  • CLI/headless operation

    wireshark
    TSharksame engine, separate binary
    tcpdump
    Documented

Filters

  • Capture-time filtering

    wireshark
    Documented
    tcpdump
    Documented

    Both use BPF syntax at capture time.

  • Post-capture display filters

    wireshark
    Rich expression language
    tcpdump
    BPF expressions only

Analysis

  • Protocol dissection depth

    wireshark
    Very high
    tcpdump
    Summary level
  • Stream reassembly view

    wireshark
    Documented
    tcpdump
    Not a feature
  • Statistics and graphs

    wireshark
    Documented
    tcpdump
    Not a feature

Deploy

  • Installed by default on most servers

    wireshark
    Not a feature
    tcpdump
    Very common
  • Capture file interoperability

    wireshark
    pcap/pcapng
    tcpdump
    pcap

    Files move freely between the two.

Wireshark

GUI analysis with protocol dissection, statistics, coloring rules, streams and filters over a full capture.

Strengths

  • Deepest dissection catalogue of any open tool
  • Follow-stream view for application exchanges
  • Statistics: conversations, I/O graphs, expert info
  • Profiles and saved display filters

Limitations

  • GUI-centric
  • Capture on a remote headless host is not its environment

Consider Wireshark when

  • — Detailed protocol questions
  • — Teaching and walkthroughs
  • — Large captures needing navigation

tcpdump

libpcap capture with BPF filtering and text output, present on almost every Unix.

Strengths

  • Runs anywhere, tiny dependency footprint
  • Write bounded capture files for later analysis
  • Read filters to re-query saved files

Limitations

  • No dissection depth by default
  • No interactive filtering while capturing

Consider tcpdump when

  • — On the server, in a container, over SSH
  • — Evidence capture with a size cap
  • — Quick yes/no on reachability
Open tcpdump documentation

The same job, both ways

Capture on the host, analyse on the workstation

wireshark

Open the file, apply `tcp.analysis.retransmission`, then follow the suspect stream

tcpdump

sudo tcpdump -i eth0 -w /tmp/incident.pcap -C 50 -W 4 'host 192.0.2.10 and port 443'

Copy the capture off the host under the same evidence handling as any other artefact.

Sources

Both columns should be checkable against upstream documentation.