Wireshark
network analysis
The world's most popular network protocol analyzer. Capture and interactively browse traffic on a computer network with deep inspection of hundreds of protocols.
packet captureprotocol analysistraffic inspection
Legal & Ethical Use
- Network troubleshooting
- Protocol analysis and learning
- Security analysis on authorized networks
- Application debugging
Installation
bash
$
sudo apt install wiresharkBasic Commands
bash
$
wiresharkLaunch GUI interface
bash
$
tshark -i eth0CLI capture on interface
bash
$
tshark -r capture.pcapRead capture file
bash
$
tshark -i eth0 -f "port 80"Capture HTTP traffic only
Advantages
- Comprehensive protocol support
- Powerful filtering
- GUI and CLI options
- Cross-platform
Limitations
- Can be resource intensive
- Large captures need storage
- Learning curve for filters