Skip to content

Wireshark

Packet capture and analysis tool, with TShark as its command line counterpart.

When I Use It

  • Analyzing a packet capture from an incident or an IDS alert
  • Confirming what a suspicious host is actually sending, beyond what flow logs show
  • Extracting files and credentials transferred in cleartext protocols
  • Practicing with capture-based challenges

Installation

Common Tasks

Capture Filters

BPF syntax, set before a capture starts to limit what is recorded.

Goal Filter
Traffic to and from an IP host 192.168.1.1
A subnet net 192.168.0.0/24
Packets sent to a host dst host 192.168.1.1
One port port 53
Everything except DNS and ARP not port 53 and not arp

Display Filters

Applied to captured traffic.

Goal Filter
Traffic from one host to another ip.src == 10.0.0.5 and ip.dst == 10.0.0.10
All traffic for a host ip.addr == 10.0.0.5
All traffic except a host !(ip.addr == 10.0.0.5)
A TCP port tcp.port == 25
ICMP only icmp
TLS from a host on port 443 ip.src == 192.168.1.7 and tcp.port == 443 and tls
TLS server names (SNI) tls.handshake.extensions_server_name contains "example"
DNS queries for a domain dns.qry.name contains "example"
HTTP POST requests http.request.method == "POST"
HTTP redirects http.response.code == 301 or http.response.code == 302
A string anywhere in a frame frame contains "string"
DHCP (hostnames are in the Host Name option of DHCP Requests) dhcp
SYN scan pattern tcp.flags.syn == 1 and tcp.flags.ack == 0

Searching and Extracting

Task Steps
Search packets for a string Ctrl + F
Follow a conversation Right click -> Follow -> TCP/UDP/TLS/HTTP Stream
Extract files from HTTP File -> Export Objects -> HTTP -> select file -> Save
Extract files from FTP Filter ftp-data -> right click -> Follow -> TCP Stream -> Show data as Raw -> Save
Extract files from other streams Follow TCP Stream -> Show data as Raw -> Save, then check with ExifTool or fix the file extension
Resolved hostnames Statistics -> Resolved Addresses

TShark

# Apply a display filter to a capture
tshark -r capture.pcap -Y "http.request"

# Print selected fields: source IP and DNS query name
tshark -r capture.pcap -Y dns -T fields -e ip.src -e dns.qry.name

Reading the Output

I start with the statistics windows before reading individual packets:

Window What It Shows
Statistics -> Protocol Hierarchy Which protocols are in the capture, and how much of each
Statistics -> Conversations Which hosts talked to each other, and how much data moved
Statistics -> Endpoints Every host in the capture, sortable by traffic

A host sending far more data out than it receives, or a protocol that should not be there (SMB to the internet, DNS to a server that is not your resolver), is where I dig in.

Resources