Skip to content

Wireshark

Protocol analyzer for capturing and inspecting network traffic

VerifiedNetworking· Traffic AnalysisBeginnerGPL-2.0-or-laterOpen sourceEntry revised 16 Jan 2026
  • Windows
  • macOS
  • Linux
  • Kali
  • Parrot
  • Arch
  • Fedora
  • Docker
  • Source

Overview

8 commands documented

Wireshark captures packets from an interface and decodes them into protocol trees, so you can read exactly what crossed the wire: handshakes, retransmissions, credentials sent in the clear, application behaviour.

It is primarily a diagnostic instrument. Engineers use it to explain why a connection is slow or failing; analysts use it to reconstruct what a host actually said during an incident. TShark is the same engine without the GUI, which makes it usable on servers and in scripts.

Supported platforms

9

Documented install or usage guidance

Learning curve

beginner

Difficulty of becoming productive, not of the underlying theory

Tags

pcap, capture, protocol, analysis, display filter, tshark

Dataset entry

wireshark.ts

Reviewed 2026-01-16

Installation

Grouped by platform. Elevation requirements are marked per method.

Official installer (includes Npcap)

RecommendedinstallerOfficial

The Windows installer bundles Npcap. During setup, keep the default capture settings unless your organisation's policy says otherwise.

Needs elevated privileges (sudo / Administrator).

  • Installers are signed per release; compare the hash shown on the download page if you verify packages.
Open official source

Winget

Alternativewinget

Needs elevated privileges (sudo / Administrator).

winget install --id WiresharkFoundation.Wireshark -e

Package availability follows your distribution and enabled repositories. Entry revised 16 Jan 2026 — confirm the current release on the project's own download page.

Commands

8 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Capture on a specific interface

bash

Live capture from one interface, bounded by packet count so the file stays reviewable.

tshark -i eth0 -c 5000 -w /tmp/lab.pcapng

Notes

  • List interfaces first: `tshark -D`. On Windows the interface names include \Device\NPF_ prefixes.

02Show one conversation only

bash

Display filters narrow a capture while reading it, without losing the underlying packets.

tcp.port == 443 && ip.addr == 192.0.2.10

Example

tshark -r lab.pcapng -Y 'http.request.method == "GET"' -T fields -e frame.number -e http.host

Notes

  • `-Y` applies a display filter; `-f` applies a capture (BPF) filter while recording. They are different languages.

03Reassemble a TCP stream

bash

Rebuilds the byte stream of one TCP conversation so the application-layer exchange reads as text.

tshark -r lab.pcapng -q -z follow,tcp,ascii,0

Notes

  • In the GUI use Follow → TCP Stream. If the stream is TLS-encrypted you will see ciphertext unless you also have the session keys.

04Decrypt TLS with a key log file

bash

When the client writes a key log, Wireshark can decrypt the session and decode HTTP/1.1 or HTTP/2 inside it.

SSLKEYLOGFILE=/tmp/keys.log curl -s https://example.internal/ >/dev/null

Notes

  • Point Preferences → Protocols → TLS at (Pre)-Master-Secret log filename, then capture. This only ever works for traffic where you legitimately hold the client keys — your own browser in a lab.
  • Never attempt to decrypt sessions belonging to other parties without explicit authorization.

05Reduce data at capture time

bash

BPF capture filters write only what you need, which matters on busy links.

sudo tcpdump -i eth0 -w /tmp/dns.pcap 'port 53'

Notes

  • The same BPF expression works in Wireshark's capture options. Capture filters cannot match application content, only L2-L4 fields.

06Rank endpoints and conversations

bash

Quick statistical view of who talked to whom and how much — the fastest way to orient in a large capture.

tshark -r lab.pcapng -q -z conv,tcp

Notes

  • In the GUI: Statistics → Conversations / Endpoints / Protocol Hierarchy.

07Find retransmissions and errors

bash

Expert information aggregates anomalies so a slow-application investigation starts with evidence, not guesswork.

tshark -r lab.pcapng -Y 'tcp.analysis.retransmission || tcp.analysis.zero_window' -T fields -e frame.time_relative -e ip.src -e ip.dst

Example output

Illustrative only — real output depends on the target, version and your position on the network.

0.302114000	192.0.2.10	192.0.2.20
0.641223000	192.0.2.10	192.0.2.20

Notes

  • Retransmissions at one side plus a zero-window from the other points to a receive-buffer problem, not a network problem.

08Extract transferred files

bash

Pulls files reassembled from an SMB, HTTP or FTP stream — used in labs and incident review to recover a delivered artefact.

tshark -r lab.pcapng -q -z export_objects,http
  • Treat extracted files as untrusted. Do not open recovered executables outside an isolated VM.

Worked examples

Sequences of commands in the order they are used, with what you should expect to learn from each.

Why does this internal API feel slow?

A service responds in 3 s on one segment and 200 ms on another.

  1. 1

    Capture near the client with a bounded file size

    sudo tshark -i eth0 -f 'host 192.0.2.30 and port 8443' -a duration:60 -w api.pcapng
  2. 2

    Measure TCP-level delay per request

    tshark -r api.pcapng -Y 'tcp.analysis.flags' -T fields -e frame.time_relative -e tcp.analysis.type
  3. 3

    Compare handshake RTT to total response time

    tshark -r api.pcapng -Y 'tcp.handshake.time' -T fields -e tcp.handshake.time -e frame.time_relative

If the handshake RTT is small and the delay sits between request and response, the application is the bottleneck — not the network.

What it is used for

  • Protocol learning

    See what a handshake actually contains instead of reading about it.

  • Service troubleshooting

    Separate network faults from application faults with evidence.

  • Incident reconstruction

    Establish what a host transmitted during a window of interest.

  • Filter and rule validation

    Confirm a firewall or proxy behaved as intended.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

"You don't have permission to capture on this adapter"Cause 1/4

Possible causes

  • The user is not in the capture group (Linux) or Npcap/ChmodBPF is not configured (Windows/macOS).
  • Pktmon is in use on Windows instead of Npcap.

Usual fix

On Linux add the user to the wireshark group and re-login. On macOS run the install_chmodbpf script from the Wireshark package. On Windows re-run the installer with Npcap selected.

sudo usermod -aG wireshark $USER
ls -l /dev/bpf*
Capture is full of 'TCP Out-Of-Order' or duplicate framesCause 2/4

Possible causes

  • NIC offload features (GRO/TSO/LRO) rewrite packets before capture.

Usual fix

Disable offload on the capture interface for the duration of the test, or read the capture as indicative rather than authoritative.

sudo ethtool -K eth0 gro off tso off lro off
Only 'TLS' and 'Continuation Data' lines, nothing readableCause 3/4

Possible causes

  • Traffic is encrypted (expected) and no key log is loaded.

Usual fix

Decode only what you are allowed to: export your own browser's SSLKEYLOGFILE in a lab, or analyse certificate and timing metadata instead.

Filtered on 'http' but the site clearly uses HTTP/2Cause 4/4

Possible causes

  • Field names differ per dissector.

Usual fix

Filter on `http2` fields (`http2.headers.path`) or expand the protocol tree to see the correct field names for your version.

Tips

  • Name your display filters (left-click a filter field while holding the modifier key) and reuse them — half of analysis is typing the same filter again.
  • Enable time-shift display (`View → Time Display Format → Seconds Since Beginning of Capture`) before you compare two events.
  • For long captures, capture to a ring buffer (`-b filesize:65536 -b files:10`) instead of one huge file.
  • Read `frame.time_relative`, not wall-clock, when you are measuring durations.

Alternatives & comparisons

Not documented yet: tshark. Request an entry and it will link up automatically.Request a tool

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Networking

Looking for alternatives?

tcpdump cover adjacent parts of the same job.

Compare side by side