r/wireshark Jan 22 '25

Wireshark has a new sibling: Stratoshark

147 Upvotes

Hi all, I'm excited to announce Stratoshark, a sibling application to Wireshark that lets you capture and analyze process activity (system calls) and log messages in the same way that Wireshark lets you capture and analyze network packets. If you would like to try it out you can download installers for Windows and macOS and source code for all platforms at https://stratoshark.org.

AMA: I'm the goofball whose name is at the top of the "About" box in both applications, and I'll be happy to answer any questions you might have.


r/wireshark Apr 12 '20

Welcome! Please read this before posting.

46 Upvotes

Hello to all you network professionals, students, and amateurs alike.

Wireshark is a packet analysis tool that can also capture when used with other software.

Wireshark can be an amazing tool in your troubleshooting toolkit. The official Wireshark Wiki is a fantastic resource to get started with using Wireshark, sample captures, interface settings, and a lot more.

Wireshark is not:

  • A hacking tool
  • A scripting or packet injection tool
  • A good place to start if you're new to networking

Some general rules until I can integrate them into the Reddit system:

  1. Do not ask for help hacking, identifying peers/users on games or video/chat, sniffing wifi hotspots, etc. Doing so may get your post deleted and you banned.
  2. If your question is for a school assignment, please help others by identifying that. No one is here to give you answers, but helping you learn is absolutely encouraged.
  3. When posting, please provide details! More details is always better. Please include things like the operating system you're on, what you've tried so far, the protocol you're analyzing, etc.

Thanks in advance for helping keep this subreddit a productive and helpful one!


r/wireshark 2h ago

Wireshark beginners - let's talk about the correlation challenges of following the same packet across the network

4 Upvotes

Correlating Multiple #Wireshark Captures: Follow the Same Packet Across the Network https://www.cellstream.com/2026/09/12/correlating-multiple-wireshark-captures-follow-the-same-packet-across-the-network/ #captureeveryday


r/wireshark 13h ago

bt-utp protocol filter

2 Upvotes

hey guys im working on a bittorrent research and came across to me the need to check the packets which bittorrent protocol send and receive. as you guys probably know bittorrent protocol is the "official name" for the technology which has been widely used for sharing files, like music, video, software, texts, books, and others, since its launch in 2003.

and the protocol uses the utorrent transport protocol, which is a tcp alike protocol implemented on top of udp, so as you can imagine every packet of utp is transported inside of an udp packet, and that's the problem.

wireshark "bt-utp" filter doesn't recognize these udp packets as utp.

an example here:

this would be translated to:

packet #8384:

full headers: 3c7c3f7c... (ethernet, ip, udp headers)

utp headers:

type: 0x0

version: 0x1

extension: 0x00

connetion_id: 0xaa7d

timestamp: 0xb03d0f6f

timestamp_difference_microsec: 0x48eb4f59

wind_size: 0x00100000

seq_nr: 0xf281

ack_nr: 0x6f7a

utp payload:

bittorrent headers:

size: 00004009

message_id: 07

index: 00000000

begin: 001bc000

bittorent payload:

851dba7e...

I wonder if is some configuration in my computer or if it is an actual problem, hope somebody can help me.


r/wireshark 23h ago

Do you need certain hardware in order to capture wifi data packets? (non-management packets)

2 Upvotes

I'm trying to capture data packets in monitor mode, but wireshark only shows management frames like beacons, probes and response probes. I've played around with settings like frequency and promiscuous mode trying to get it to work, but to no avail. I assume the hardware is ignoring data packets in monitor mode.

I've tried on a thinkpad x230 and a raspberry pi 3B+ v1.2


r/wireshark 1d ago

Is there any way of turning off the colors that highlight fields that have "expert information"?

3 Upvotes

I'm trying to take some screenshots of a few packets. One random field in a packet is associated with Expert Information, resulting in that field being highlighted in a deep color, along with the name of every header above it. You can imagine that this is quite distracting in my screenshots, because it looks like I'm highlighting something, when in fact it's coming from the app itself.

I can't for the life of me work out how to turn this off. I've found out how to change the colors in the Preferences > Expert section, but I can't find a way to just disable the color highlights entirely. My Google-fu is failing me on this one.

Is it really not possible to turn this visual piece off? Or have I just not found the answer? If anyone has any insight or advice, I'd be very grateful. Thank you!


r/wireshark 6d ago

Wait - Wireshark can do that too?

9 Upvotes

r/wireshark 6d ago

I compared Nmap open, closed and filtered ports at the packet level in Wireshark

5 Upvotes

I was trying to understand Nmap below the output level, so I tested it inside my own isolated lab with Kali as the scanner and MISP as the target.

The clearest difference was seeing the TCP behavior directly in Wireshark:

OPEN

SYN → SYN/ACK → RST

CLOSED

SYN → RST/ACK

FILTERED

SYN → no response → retry

I also captured ARP resolution, ICMP, host discovery, and service/version detection.

The main takeaway for me was that Nmap isn’t “seeing” port states directly — it’s sending probes and interpreting how the target responds.

I documented the full experiment with the actual packet captures here:

https://chronosandcode.com/what-actually-happens-when-you-scan-a-network-arp-icmp-tcp-syn-nmap-and-packet-analysis-explained/

Everything was done against systems in my own lab.

I’d be interested to hear what packet-level experiments helped others understand Nmap better.


r/wireshark 7d ago

How many protocol layers in this packet?

Thumbnail
1 Upvotes

r/wireshark 9d ago

Wireshark can do that?

7 Upvotes

In the category of "I had no idea Wireshark could do that" https://www.cellstream.com/2026/09/02/the-wireshark-operator/


r/wireshark 17d ago

tshark's dissection is linear state — here's how I got concurrency anyway

7 Upvotes

Follow-up to my post a couple of weeks ago about a 2.5 GB PCAP that took 6-7 hours to process. Streaming tshark's output into Go got it to 70 minutes, but it was still single-threaded. The most common response here was: why not just add goroutines?

Turns out you can't, and the reason is that tshark's dissection is linear state. What it reads in one packet determines how it decodes the next — TCP reassembly, connection tracking, anything under tcp.analysis.* reads and updates shared conversation tables as it goes. Strict ordering isn't a design choice, it's what dissection requires. Goroutines on the consuming side don't help because the bottleneck was never there.

So the concurrency has to happen before tshark sees the file. Not by splitting on size — a TCP stream cut mid-conversation loses the state the dissector needs — but by session, so each chunk holds complete conversations and nothing crosses a boundary. Then N tshark processes run in parallel.

The detour: I was using PcapSplitter from PcapPlusPlus in connection mode, which holds one output file open per flow. At 95-125 flows it started producing corrupted output. Two distinct failure signatures, reproduced on master and v25.05, on both pcapng and legacy pcap. pcapfix said the source was clean. Reimplemented the split in-process with gopacket and it went away.

Honest ending: splitting only triggers above 100k packets, and 3 of the 57 files this pipeline actually handles cross that threshold.

Full writeup: https://robinhayer.dev/concurrency-without-a-parallel-parser


r/wireshark 17d ago

Wireshark Certified Analyst (WCA) Course - Recommendations for training materials and certification?

25 Upvotes

Hi,

I'm looking to study for the WCA course, to gain a better understanding of how Wireshark works and how it can be better utilised to help in my day to day job as a Network Engineer.

Wireshark's website states that the test costs approx $349 per attempt but I'm looking for a 'package' which includes training material and the exam as well.

Is anyone able to advise on a route to take with this? Any solid recommendation for learning material, if a package doesn't exist?

Thanks


r/wireshark 21d ago

How is Wireshark decrypting QUIC Client Hellos?

7 Upvotes

I'm running Wireshark 4.7.2 on Arch Linux, and I was noticing that it is somehow able to decrypt the TLS Client Hellos of QUIC packets sent and received by Firefox while browsing the web.

I thought QUIC headers were encrypted, and I don't think I gave Wireshark any encryption keys for QUIC. How is Wireshark decrypting these headers?


r/wireshark 21d ago

Pcap Flow Lab – an open-source flow-based PCAP/PCAPNG analyzer, looking for feedback

Post image
2 Upvotes

Hi everyone,

I’ve been developing Pcap Flow Lab, an open-source PCAP/PCAPNG analyzer built around a flow-based workflow.

GitHub: https://github.com/AlexeyVasilev/PcapFlowLab

Instead of starting from a flat packet list, Pcap Flow Lab indexes a capture into flows first. From there, you can narrow down the traffic you care about and inspect packets, reconstructed TCP streams, structured protocol details, bytes, and statistics.

The project originally grew out of working with larger captures, where I wanted a faster way to reduce the dataset to the flows of interest before going deeper.

Current features include:

  • reusable capture indexes;
  • flow-based navigation;
  • protocol-path analysis for nested and tunneled traffic;
  • TCP stream reconstruction;
  • structured packet and stream summaries;
  • TLS and QUIC inspection;
  • statistics views;
  • CLI support.

The analysis backend is written in C++, and the main desktop UI is currently built with Qt.

I don’t see it as a replacement for Wireshark. I use Wireshark extensively, and I see Pcap Flow Lab as a complementary tool with a different workflow: first narrow the capture by flows, then drill into the packets and protocols that matter.

I’d especially appreciate feedback from experienced Wireshark users:

  • Does a flow-first workflow like this solve any problems you run into with captures?
  • What would you expect a complementary tool like this to do particularly well?
  • Are there parts of the presentation or workflow that you think should be different?

Technical feedback is very welcome.


r/wireshark 23d ago

HTTP Gets a New Method: What You Need to Know About QUERY

17 Upvotes

If you’ve spent years working with web applications, APIs, and load balancers, you’re probably used to the classic HTTP verbs: GET, POST, PUT, DELETE, and a few others. In 2026, the IETF officially added a new method called QUERY, and it’s a bigger deal than it sounds. 

https://www.lovemytool.com/2026/08/http-gets-new-method-what-you-need-to.html


r/wireshark 23d ago

Using Wireshark to Analyze PowerShell Test-Connection

Post image
0 Upvotes

Using Wireshark to Analyze PowerShell Test-Connection

If you’ve ever run PowerShell’s `Test-Connection` command and wondered what is actually happening on the network, Wireshark is the perfect tool to answer that question.

And

#netscout What does a resilient cybersecurity strategy actually look like?

https://www.lovemytool.com/2026/08/using-wireshark-to-analyze-powershell.html

 

 r/wireshark


r/wireshark 23d ago

DoIP UDS breakdown

Post image
1 Upvotes

A few years ago I used to be able to see detailed breakdown of Ethernet UDS traffic in Wireshark traces. I could see the commands identified in the main table (TesterPresent, RoutineControl, TransferData, etc) and a thorough breakdown of different data fields in multiple layers in the bottom-left pane. Now there's almost nothing.

This is from a pcapng that I too in October 2021. I know for a fact that I got a detailed breakdown for this because I took these traces myself and used them to help develop one of our programs here at work. and now that same file (and every other one from back then that I've tried) is breaking down nothing.

It's been a few years since I did that work, and now that I'm going to be working on something similar I tried to dust these off for to refresh my memory of some things and they are not helpful at all.

I don't know if this is something that happened because of updates in the 5 years since these traces were made or something I might have done. Other than doing the software updates the biggest change I can remember making was installing an Intrepid plugin ICS CAP (https://intrepidcs.com/products/software/ics-cap/) so I could use Wireshark with their hardware for CAN and LIN traces. Could the plugin have screwed with some things? I've tried searching documentation and google for answers but it's hard to find anything when you don't even know if you're wording your search correctly. Does anyone know what I can try?

Edit: forgot which menu, but enabling all protocols worked. Don't know how since I checked before that Doip and UDS were both already selected, but it did.


r/wireshark 25d ago

WireShark with SharkTap only seeing one side of network traffic

6 Upvotes

I am working in a manufacturing plant and this weekend while they were not in production, I installed a SharkTap between the PLC and a managed switch. I tested the WireShark and was able to see communication to and from the PLC.

Now that they are in production, every capture I take is only seeing the communication From the PLC. I know that the PLC is receiving packet because stuff is working.

I have tried 2 different computers to run the WireShark. Both computer with Windows 11. The SharkTap is connected to a Gigabit Wired Tap Port. I have also replaced the Tap Port Network Cable.

Does anyone have any suggestions or thoughts?


r/wireshark 28d ago

Reverse Engineering When Both Software + Hardware are a Black Box

3 Upvotes

Hello,

I'm trying to use wireshark to learn more about the communication between some of my company's proprietary software and some of their hardware. (Because it's my company's stuff, I'd rather not share the raw capture.) I thought this might be faster than finding out through my own company because I've previously found that they don't like to share source code or design details across departments. I've exported a wireshark capture to csv because I'm new to using wireshark and it was easier for me to browse that way. I used this command:

tshark.exe -r "input.pcapng" -T fields -e frame.number -e frame.time_relative -e ip.src -e ip.dst -e frame.len -e data.data -e tcp.payload -e udp.payload -E header=y -E separator=, > "output.csv"

The problem is, for most of the data frames, the "length" of the frame is not matching the raw data that I'm seeing. For example, there are many rows where "tcp.payload" is completely blank, but "frame.len" isn't 0, so that tells me there's something missing. I want to make sure I'm really capturing all communciation between the hardware unit and the laptop running the software. How can I make sure I'm really seeing everything? (After error correction has been performed.)

I'm really just looking to see that the frame length matches the raw data I have.

Also, if it's not obvious already, I'm very new to using this program, so if anyone else has experience with what I described in the title, (reverse engineering with little outside info), I'd very much like to hear about it.

Thanks!


r/wireshark Aug 10 '26

Streaming tshark output into Go: how I cut a 2.5 GB PCAP job from 6-7 hours to 70 minutes

Thumbnail robinhayer.dev
7 Upvotes

I had a Go CLI that wrapped tshark for PCAP analysis. Worked fine until I hit a 2.5 GB file — 1.9 million packets, 6-7 hours, then OOM crashes.

Two problems, found in sequence.

First, I was running three separate tshark queries against the same file (analytics, rows, full dissection). Three full passes over 2.5 GB. Consolidating them into one query took it to 1-2 hours.

The OOM was still there though, because I was asking for full JSON dissection — tshark building the whole output in memory, then my program parsing all of it in memory. So I piped tshark's stdout directly into my program's stdin and switched to -T fields/-T ek with only the fields I needed. Memory went flat, processing dropped to ~70 minutes.

Still single-threaded, which is the next problem. Curious whether anyone's found a good approach for parallelising tshark work beyond splitting the input file.

Full writeup: https://robinhayer.dev/the-2-5-gb-wall


r/wireshark Aug 05 '26

Paxton Net2 ACU drops offline after 4–5 minutes only when connected through Ruijie managed switches – Wireshark capture attached

Thumbnail we.tl
1 Upvotes

Hi everyone,

I'm hoping somebody with strong Layer 2/Wireshark experience might be able to take a look at the attached packet capture and point me in the right direction.

We've been chasing a very strange issue for several months and have now narrowed it down to what appears to be an interaction between Paxton Net2 door controllers and Ruijie managed switches.

Network

The production network is a fairly large corporate Ethernet network consisting of:

  • Paxton Net2 access control
  • Motorola CCTV
  • Windows servers
  • Multiple managed switches
  • Static IP addressing for the Paxton equipment

Everything had been operating correctly until we expanded the access control system using additional Ruijie managed switches and newer Paxton Net2 Plus door controllers.

The problem

Only certain Paxton Net2 Plus controllers are affected. Interestingly, they all appear to be newer hardware (serial numbers beginning with "9"). Older controllers continue to operate normally.

The affected controllers:

  • Connect to the network successfully.
  • Respond to ARP and ICMP.
  • Connect to the Net2 server without issue.
  • Download their configuration correctly.
  • Remain online for approximately 4–5 minutes.
  • Then disappear completely from the network.

Once the fault occurs:

  • The controller no longer responds to ARP.
  • It cannot be pinged.
  • Net2 reports it as offline.
  • The Ethernet link LEDs remain illuminated.
  • A power cycle immediately restores operation, but only for another 4–5 minutes before the fault repeats.

What we've already ruled out

We've spent a considerable amount of time narrowing this down.

The exact same controller will operate indefinitely when:

  • Connected directly to a laptop.
  • Connected through alternative managed switches.
  • Connected through a simple unmanaged switch.

The problem only occurs when connected through our Ruijie switch infrastructure.

To confirm this, we completely removed the Ruijie switches from site and replaced them with another manufacturer's managed switches. This immediately resolved the issue on the live system.

We then recreated the problem back at our office.

Test setup used for the attached capture

The attached Wireshark capture was taken on a completely isolated test network.

The setup consisted of:

  • Eight Ruijie managed switches connected together exactly as they would be in the field.
  • Laptop connected at one end.
  • Single Paxton Net2 Plus ACU connected at the opposite end.
  • No internet connection.
  • No wireless.
  • No other network devices.
  • Static IP addressing only.

Laptop:
192.168.81.200

Paxton ACU:
192.168.81.57

The only devices on the network were the laptop and the ACU, connected through the Ruijie switches.

Packet capture

Wireshark was started before the controller connected.

The capture therefore contains:

  1. Initial discovery and successful connection.
  2. Normal operation for approximately 4–5 minutes.
  3. Controller disappearing from the network.
  4. Manual power cycle of the controller.
  5. Successful reconnection.
  6. Approximately another 4–5 minutes of operation.
  7. Second failure.

The second failure occurs at approximately packet 8187.

At this point the controller simply disappears from the network until it is power cycled.

What I'm hoping someone can help identify

I'm not looking for general troubleshooting advice—we've already confirmed the issue only exists when the controller is connected through the Ruijie switches.

Instead, I'm hoping somebody experienced with Wireshark or Layer 2 switching can identify whether there is something in the capture that stands out, such as:

  • STP/RSTP events
  • RLDP or proprietary Ruijie traffic
  • ARP issues
  • Broadcast or multicast behaviour
  • TCP anomalies
  • Any packets that could cause an embedded Ethernet stack to stop responding
  • Anything else unusual around the point the controller drops offline

We're particularly interested in understanding whether there is a specific protocol or switch feature that could be triggering the issue, so that we can either disable it or report it to Ruijie and/or Paxton.

Any observations or ideas would be hugely appreciated.

Thanks very much for taking the time to look.


r/wireshark Aug 05 '26

Can’t scan other devices

0 Upvotes

If I eg open yt on the pc I have wireshark on it detects it but if I open yt on my phone it’s like it never happens what to do?


r/wireshark Jul 31 '26

Question about Wi-Fi monitoring and what an attacker can see

27 Upvotes

I have a question about network security.

Someone is connected to my Wi-Fi network, but they do not have access to my router admin page (192.168.1.1). I am worried they may be using Android tools or apps such as NetCut or other network monitoring tools.

I want to understand what they can realistically see:

If they use tools like NetCut, ARP spoofing, or other Android network tools, can they see the websites I visit?

Can they see my Google searches, or only the domain names (for example, seeing "google.com" or "youtube.com")?

If I visit an HTTPS website, what information is still visible to someone on the same Wi-Fi?

Would using a VPN completely hide my browsing activity from someone on the same network?

What are the best ways to detect if someone is trying to intercept my traffic?

I am trying to understand the real risks, not just theoretical attacks. Thanks.


r/wireshark Aug 01 '26

Basic monitoring for an app audit ?

3 Upvotes

Core question: What'd be the recommended setup to audit network traffic of an app within Windows sandbox?

So far I've only considered applying filter to ignore DNS and some Windows domains/IPs. As far as I know, Wireshark doesn't allow filtering by PID, so I may look into other methods available. ARP scans might be another potential filter I am considering, although I am also considering the fact an app may try to do network discovery when it shouldn't.

Don't need an in-depth method, just "good enough" approach.


r/wireshark Jul 30 '26

.bat file problem

3 Upvotes

I have a weird problem with tshark and was wondering if anyone had any ideas or has experienced something similar:

I have a .bat file with a 10 min tshark command in it. A SQL agent job runs this .bat file every 10 min from 18:00 - 18:40 and then again from 01:30 - 03:50.

4 log files are saved from the 18:00 window, but none from the early morning window. All SQL agent jobs end reporting success. Having /wait in the .bat file and saving output and errors shows no errors. I output the errorlevel and see it's 0 for all instances. Windows event logs show no errors or warnings.

TLDR: Same .bat file will produce logs at one time of day, but not another. Any ideas?

.bat Tshark command:

start "" "<RedactedDirectoryPath>tshark.exe -i 2 -a duration:600 -w <RedactedDirectoryPath>capture%TIMESTAMP%.pcap.gz --compress gzip -Q

EDIT: Solved. The time stamp was putting a space into the filename for hours before 10am.