You must have tshark 2.4.0 or higher to use the
tshark has the ability to reassemble files provided a packet capture. These list includes HTTP, SMB, IMF, DICOM, and TFTP for latest Wireshark. This section covers how to extract files from HTTP in both encypted and unencypted captures.
Export 5 file types from captures
Export files from a capture encrypted with TLS 1.2/1.3