Wireshark

Packet Analysis Reference

CaptureDescription
Start CaptureBegin packet sniffing
Capture FilterLimit packets by protocol/IP
Interface ListChoose network interface
Save .pcapExport capture file
Display FiltersDescription
ip.addr == 192.168.1.1Filter by IP address
tcp.port == 443Filter by TCP port
httpShow HTTP traffic
dnsShow DNS queries
AnalysisDescription
Follow TCP StreamView full conversation
Statistics → Protocol HierarchyBreak down traffic types
Expert InfoHighlight anomalies
IO GraphsVisualize traffic over time
ProtocolsDescription
ARPAddress Resolution Protocol
ICMPPing and echo requests
TLSEncrypted traffic
DHCPIP assignment traffic
Export & ToolsDescription
Export Packet BytesSave raw data
Export Objects → HTTPExtract files from traffic
Color RulesHighlight traffic types
Command Line: tsharkCLI version of Wireshark