Wireshark

Packet Analysis Reference

📡 Capture

CommandDescription
Start CaptureBegin packet sniffing
Capture FilterLimit packets by protocol/IP
Interface ListChoose network interface
Save .pcapExport capture file

🔍 Display Filters

CommandDescription
ip.addr == 192.168.1.1Filter by IP address
tcp.port == 443Filter by TCP port
httpShow HTTP traffic
dnsShow DNS queries

📊 Analysis

CommandDescription
Follow TCP StreamView full conversation
Statistics → Protocol HierarchyBreak down traffic types
Expert InfoHighlight anomalies
IO GraphsVisualize traffic over time

📦 Protocols

CommandDescription
ARPAddress Resolution Protocol
ICMPPing and echo requests
TLSEncrypted traffic
DHCPIP assignment traffic

🛠️ Export & Tools

CommandDescription
Export Packet BytesSave raw data
Export Objects → HTTPExtract files from traffic
Color RulesHighlight traffic types
Command Line: tsharkCLI version of Wireshark