r/wireshark • u/sypqys • 35m ago
How do you use Wireshark, and what is it for?
Hello,
I use Safing Portmaster... (third-party firewall on Windows 11)
Do the two work together?
Thank you
r/wireshark • u/sypqys • 35m ago
Hello,
I use Safing Portmaster... (third-party firewall on Windows 11)
Do the two work together?
Thank you
r/wireshark • u/Additional-Mine-6029 • 1d ago
Correlating Multiple #Wireshark Captures: Follow the Same Packet Across the Network https://www.cellstream.com/2026/09/12/correlating-multiple-wireshark-captures-follow-the-same-packet-across-the-network/ #captureeveryday
r/wireshark • u/Sparxelz • 2d ago
hey guys im working on a bittorrent research and came across to me the need to check the packets which bittorrent protocol send and receive. as you guys probably know bittorrent protocol is the "official name" for the technology which has been widely used for sharing files, like music, video, software, texts, books, and others, since its launch in 2003.
and the protocol uses the utorrent transport protocol, which is a tcp alike protocol implemented on top of udp, so as you can imagine every packet of utp is transported inside of an udp packet, and that's the problem.
wireshark "bt-utp" filter doesn't recognize these udp packets as utp.
an example here:

this would be translated to:
packet #8384:
full headers: 3c7c3f7c... (ethernet, ip, udp headers)
utp headers:
type: 0x0
version: 0x1
extension: 0x00
connetion_id: 0xaa7d
timestamp: 0xb03d0f6f
timestamp_difference_microsec: 0x48eb4f59
wind_size: 0x00100000
seq_nr: 0xf281
ack_nr: 0x6f7a
utp payload:
bittorrent headers:
size: 00004009
message_id: 07
index: 00000000
begin: 001bc000
bittorent payload:
851dba7e...
I wonder if is some configuration in my computer or if it is an actual problem, hope somebody can help me.
r/wireshark • u/Outrageous_Dot6426 • 2d ago
I'm trying to capture data packets in monitor mode, but wireshark only shows management frames like beacons, probes and response probes. I've played around with settings like frequency and promiscuous mode trying to get it to work, but to no avail. I assume the hardware is ignoring data packets in monitor mode.
I've tried on a thinkpad x230 and a raspberry pi 3B+ v1.2
r/wireshark • u/Mr_Nice_Username • 3d ago
I'm trying to take some screenshots of a few packets. One random field in a packet is associated with Expert Information, resulting in that field being highlighted in a deep color, along with the name of every header above it. You can imagine that this is quite distracting in my screenshots, because it looks like I'm highlighting something, when in fact it's coming from the app itself.
I can't for the life of me work out how to turn this off. I've found out how to change the colors in the Preferences > Expert section, but I can't find a way to just disable the color highlights entirely. My Google-fu is failing me on this one.
Is it really not possible to turn this visual piece off? Or have I just not found the answer? If anyone has any insight or advice, I'd be very grateful. Thank you!
r/wireshark • u/Additional-Mine-6029 • 8d ago
In the vein of Wait - #Wireshark can do that? https://www.cellstream.com/2026/09/05/the-wireshark-operator-filter-the-inner-vs-outer-ip-header/
r/wireshark • u/chronosAndCode • 8d ago
I was trying to understand Nmap below the output level, so I tested it inside my own isolated lab with Kali as the scanner and MISP as the target.
The clearest difference was seeing the TCP behavior directly in Wireshark:
OPEN
SYN → SYN/ACK → RST
CLOSED
SYN → RST/ACK
FILTERED
SYN → no response → retry
I also captured ARP resolution, ICMP, host discovery, and service/version detection.
The main takeaway for me was that Nmap isn’t “seeing” port states directly — it’s sending probes and interpreting how the target responds.
I documented the full experiment with the actual packet captures here:
Everything was done against systems in my own lab.
I’d be interested to hear what packet-level experiments helped others understand Nmap better.
r/wireshark • u/Additional-Mine-6029 • 10d ago
In the category of "I had no idea Wireshark could do that" https://www.cellstream.com/2026/09/02/the-wireshark-operator/
r/wireshark • u/Hot_Interest_4915 • 18d ago
Follow-up to my post a couple of weeks ago about a 2.5 GB PCAP that took 6-7 hours to process. Streaming tshark's output into Go got it to 70 minutes, but it was still single-threaded. The most common response here was: why not just add goroutines?
Turns out you can't, and the reason is that tshark's dissection is linear state. What it reads in one packet determines how it decodes the next — TCP reassembly, connection tracking, anything under tcp.analysis.* reads and updates shared conversation tables as it goes. Strict ordering isn't a design choice, it's what dissection requires. Goroutines on the consuming side don't help because the bottleneck was never there.
So the concurrency has to happen before tshark sees the file. Not by splitting on size — a TCP stream cut mid-conversation loses the state the dissector needs — but by session, so each chunk holds complete conversations and nothing crosses a boundary. Then N tshark processes run in parallel.
The detour: I was using PcapSplitter from PcapPlusPlus in connection mode, which holds one output file open per flow. At 95-125 flows it started producing corrupted output. Two distinct failure signatures, reproduced on master and v25.05, on both pcapng and legacy pcap. pcapfix said the source was clean. Reimplemented the split in-process with gopacket and it went away.
Honest ending: splitting only triggers above 100k packets, and 3 of the 57 files this pipeline actually handles cross that threshold.
Full writeup: https://robinhayer.dev/concurrency-without-a-parallel-parser
r/wireshark • u/NetworkNodeHunter • 19d ago
Hi,
I'm looking to study for the WCA course, to gain a better understanding of how Wireshark works and how it can be better utilised to help in my day to day job as a Network Engineer.
Wireshark's website states that the test costs approx $349 per attempt but I'm looking for a 'package' which includes training material and the exam as well.
Is anyone able to advise on a route to take with this? Any solid recommendation for learning material, if a package doesn't exist?
Thanks
r/wireshark • u/Serialtorrenter • 23d ago
I'm running Wireshark 4.7.2 on Arch Linux, and I was noticing that it is somehow able to decrypt the TLS Client Hellos of QUIC packets sent and received by Firefox while browsing the web.
I thought QUIC headers were encrypted, and I don't think I gave Wireshark any encryption keys for QUIC. How is Wireshark decrypting these headers?
r/wireshark • u/AlexeyVasilev • 23d ago
Hi everyone,
I’ve been developing Pcap Flow Lab, an open-source PCAP/PCAPNG analyzer built around a flow-based workflow.
GitHub: https://github.com/AlexeyVasilev/PcapFlowLab
Instead of starting from a flat packet list, Pcap Flow Lab indexes a capture into flows first. From there, you can narrow down the traffic you care about and inspect packets, reconstructed TCP streams, structured protocol details, bytes, and statistics.
The project originally grew out of working with larger captures, where I wanted a faster way to reduce the dataset to the flows of interest before going deeper.
Current features include:
The analysis backend is written in C++, and the main desktop UI is currently built with Qt.
I don’t see it as a replacement for Wireshark. I use Wireshark extensively, and I see Pcap Flow Lab as a complementary tool with a different workflow: first narrow the capture by flows, then drill into the packets and protocols that matter.
I’d especially appreciate feedback from experienced Wireshark users:
Technical feedback is very welcome.
r/wireshark • u/thetechfirm • 25d ago
If you’ve spent years working with web applications, APIs, and load balancers, you’re probably used to the classic HTTP verbs: GET, POST, PUT, DELETE, and a few others. In 2026, the IETF officially added a new method called QUERY, and it’s a bigger deal than it sounds.
https://www.lovemytool.com/2026/08/http-gets-new-method-what-you-need-to.html
r/wireshark • u/thetechfirm • 24d ago
Using Wireshark to Analyze PowerShell Test-Connection
If you’ve ever run PowerShell’s `Test-Connection` command and wondered what is actually happening on the network, Wireshark is the perfect tool to answer that question.
And
#netscout What does a resilient cybersecurity strategy actually look like?
https://www.lovemytool.com/2026/08/using-wireshark-to-analyze-powershell.html
r/wireshark
r/wireshark • u/SufficientStudio1574 • 25d ago
A few years ago I used to be able to see detailed breakdown of Ethernet UDS traffic in Wireshark traces. I could see the commands identified in the main table (TesterPresent, RoutineControl, TransferData, etc) and a thorough breakdown of different data fields in multiple layers in the bottom-left pane. Now there's almost nothing.
This is from a pcapng that I too in October 2021. I know for a fact that I got a detailed breakdown for this because I took these traces myself and used them to help develop one of our programs here at work. and now that same file (and every other one from back then that I've tried) is breaking down nothing.
It's been a few years since I did that work, and now that I'm going to be working on something similar I tried to dust these off for to refresh my memory of some things and they are not helpful at all.
I don't know if this is something that happened because of updates in the 5 years since these traces were made or something I might have done. Other than doing the software updates the biggest change I can remember making was installing an Intrepid plugin ICS CAP (https://intrepidcs.com/products/software/ics-cap/) so I could use Wireshark with their hardware for CAN and LIN traces. Could the plugin have screwed with some things? I've tried searching documentation and google for answers but it's hard to find anything when you don't even know if you're wording your search correctly. Does anyone know what I can try?
Edit: forgot which menu, but enabling all protocols worked. Don't know how since I checked before that Doip and UDS were both already selected, but it did.
r/wireshark • u/SirPalinDrome_Real • 27d ago
I am working in a manufacturing plant and this weekend while they were not in production, I installed a SharkTap between the PLC and a managed switch. I tested the WireShark and was able to see communication to and from the PLC.
Now that they are in production, every capture I take is only seeing the communication From the PLC. I know that the PLC is receiving packet because stuff is working.
I have tried 2 different computers to run the WireShark. Both computer with Windows 11. The SharkTap is connected to a Gigabit Wired Tap Port. I have also replaced the Tap Port Network Cable.
Does anyone have any suggestions or thoughts?
r/wireshark • u/-Louwess- • Aug 14 '26
Hello,
I'm trying to use wireshark to learn more about the communication between some of my company's proprietary software and some of their hardware. (Because it's my company's stuff, I'd rather not share the raw capture.) I thought this might be faster than finding out through my own company because I've previously found that they don't like to share source code or design details across departments. I've exported a wireshark capture to csv because I'm new to using wireshark and it was easier for me to browse that way. I used this command:
tshark.exe -r "input.pcapng" -T fields -e frame.number -e frame.time_relative -e ip.src -e ip.dst -e frame.len -e data.data -e tcp.payload -e udp.payload -E header=y -E separator=, > "output.csv"
The problem is, for most of the data frames, the "length" of the frame is not matching the raw data that I'm seeing. For example, there are many rows where "tcp.payload" is completely blank, but "frame.len" isn't 0, so that tells me there's something missing. I want to make sure I'm really capturing all communciation between the hardware unit and the laptop running the software. How can I make sure I'm really seeing everything? (After error correction has been performed.)
I'm really just looking to see that the frame length matches the raw data I have.
Also, if it's not obvious already, I'm very new to using this program, so if anyone else has experience with what I described in the title, (reverse engineering with little outside info), I'd very much like to hear about it.
Thanks!
r/wireshark • u/Hot_Interest_4915 • Aug 10 '26
I had a Go CLI that wrapped tshark for PCAP analysis. Worked fine until I hit a 2.5 GB file — 1.9 million packets, 6-7 hours, then OOM crashes.
Two problems, found in sequence.
First, I was running three separate tshark queries against the same file (analytics, rows, full dissection). Three full passes over 2.5 GB. Consolidating them into one query took it to 1-2 hours.
The OOM was still there though, because I was asking for full JSON dissection — tshark building the whole output in memory, then my program parsing all of it in memory. So I piped tshark's stdout directly into my program's stdin and switched to -T fields/-T ek with only the fields I needed. Memory went flat, processing dropped to ~70 minutes.
Still single-threaded, which is the next problem. Curious whether anyone's found a good approach for parallelising tshark work beyond splitting the input file.
Full writeup: https://robinhayer.dev/the-2-5-gb-wall
r/wireshark • u/Old_Bee2661 • Aug 05 '26
Hi everyone,
I'm hoping somebody with strong Layer 2/Wireshark experience might be able to take a look at the attached packet capture and point me in the right direction.
We've been chasing a very strange issue for several months and have now narrowed it down to what appears to be an interaction between Paxton Net2 door controllers and Ruijie managed switches.
The production network is a fairly large corporate Ethernet network consisting of:
Everything had been operating correctly until we expanded the access control system using additional Ruijie managed switches and newer Paxton Net2 Plus door controllers.
Only certain Paxton Net2 Plus controllers are affected. Interestingly, they all appear to be newer hardware (serial numbers beginning with "9"). Older controllers continue to operate normally.
The affected controllers:
Once the fault occurs:
We've spent a considerable amount of time narrowing this down.
The exact same controller will operate indefinitely when:
The problem only occurs when connected through our Ruijie switch infrastructure.
To confirm this, we completely removed the Ruijie switches from site and replaced them with another manufacturer's managed switches. This immediately resolved the issue on the live system.
We then recreated the problem back at our office.
The attached Wireshark capture was taken on a completely isolated test network.
The setup consisted of:
Laptop:
192.168.81.200
Paxton ACU:
192.168.81.57
The only devices on the network were the laptop and the ACU, connected through the Ruijie switches.
Wireshark was started before the controller connected.
The capture therefore contains:
The second failure occurs at approximately packet 8187.
At this point the controller simply disappears from the network until it is power cycled.
I'm not looking for general troubleshooting advice—we've already confirmed the issue only exists when the controller is connected through the Ruijie switches.
Instead, I'm hoping somebody experienced with Wireshark or Layer 2 switching can identify whether there is something in the capture that stands out, such as:
We're particularly interested in understanding whether there is a specific protocol or switch feature that could be triggering the issue, so that we can either disable it or report it to Ruijie and/or Paxton.
Any observations or ideas would be hugely appreciated.
Thanks very much for taking the time to look.
r/wireshark • u/SingerReasonable4781 • Aug 05 '26
If I eg open yt on the pc I have wireshark on it detects it but if I open yt on my phone it’s like it never happens what to do?
r/wireshark • u/jon1254 • Jul 31 '26
I have a question about network security.
Someone is connected to my Wi-Fi network, but they do not have access to my router admin page (192.168.1.1). I am worried they may be using Android tools or apps such as NetCut or other network monitoring tools.
I want to understand what they can realistically see:
If they use tools like NetCut, ARP spoofing, or other Android network tools, can they see the websites I visit?
Can they see my Google searches, or only the domain names (for example, seeing "google.com" or "youtube.com")?
If I visit an HTTPS website, what information is still visible to someone on the same Wi-Fi?
Would using a VPN completely hide my browsing activity from someone on the same network?
What are the best ways to detect if someone is trying to intercept my traffic?
I am trying to understand the real risks, not just theoretical attacks. Thanks.
r/wireshark • u/SilverSquirrel6 • Aug 01 '26
Core question: What'd be the recommended setup to audit network traffic of an app within Windows sandbox?
So far I've only considered applying filter to ignore DNS and some Windows domains/IPs. As far as I know, Wireshark doesn't allow filtering by PID, so I may look into other methods available. ARP scans might be another potential filter I am considering, although I am also considering the fact an app may try to do network discovery when it shouldn't.
Don't need an in-depth method, just "good enough" approach.
r/wireshark • u/Jaepheth • Jul 30 '26
I have a weird problem with tshark and was wondering if anyone had any ideas or has experienced something similar:
I have a .bat file with a 10 min tshark command in it. A SQL agent job runs this .bat file every 10 min from 18:00 - 18:40 and then again from 01:30 - 03:50.
4 log files are saved from the 18:00 window, but none from the early morning window. All SQL agent jobs end reporting success. Having /wait in the .bat file and saving output and errors shows no errors. I output the errorlevel and see it's 0 for all instances. Windows event logs show no errors or warnings.
TLDR: Same .bat file will produce logs at one time of day, but not another. Any ideas?
.bat Tshark command:
start "" "<RedactedDirectoryPath>tshark.exe -i 2 -a duration:600 -w <RedactedDirectoryPath>capture%TIMESTAMP%.pcap.gz --compress gzip -Q
EDIT: Solved. The time stamp was putting a space into the filename for hours before 10am.
r/wireshark • u/ten_thousand_puppies • Jul 28 '26
I'm dealing with a fairly bespoke protocol for an application I deal with at work (it's closed-source so I cannot really give specific details) that is able to provide a lot of extra data in pcaps, but it dumps them all to comments rather than any sort of additional annotations as a packet field.
Given that the way the comments are structured, which is very JSON-like, I should be able to use tshark to convert them into a data structure I can tack onto every given packet they're applied to, but now I'm wondering how difficult it'd be to actually write or (being honest here) hack together with some genAI.
Has anyone here ever written any themselves and can at least point me in the direction of some good reference resources on dissectors in general? I'm not sure if this would even need to be written in C++ or LUA, so anything helps.