Analyze Pcap

A capture without analysis is just 1s and 0s

ADVANCED TOPICS
ANALYZE PCAP
OBTAIN PCAP
GET STARTED
Analyze

About

Analysis is the conduit between having data and communicating the result. The Wireshark suite offers multiple tools that provide this conduit. This section covers how to use tshark and friends to serve this purpose.

When in doubt, consult relevant RFCs, protocol documentation, and product manuals.

Table of Contents

  • Get Info
  • Get info from a packet capture

    • Capinfos
    • Get info from a packet capture

    • Rawshark
    • Waste time faster with someone else's bespoke solution!

  • Packet Hunting
  • Find info about packet capture

    • Display Filters
    • Find the packets you are looking for

    • dftest
    • Deconstruct Display Filters

    • Basic Analysis
    • The ultimate authority must always rest with the individual's own reason and critical analysis. – Dalai Lama