We have been asked countless times over the years to share, and provide a sharing place for, Wireshark Profiles. You can also find these profiles on Github: https://github.com/amwalding/wireshark_profiles
Wireshark profiles allow you, the user, to customize the Wireshark GUI, to tune Wireshark, to a particular protocol, to a particular view, or to a particular task. This is accomplished by changing preferences, color rules, display and capture filters, columns and contents, and much more.
As most of you who are Wireshark users know, this is perhaps the most important capability of Wireshark that speeds troubleshooting and elimination of false positives. Check out this video on the power of Wireshark Profiles:
Yet there are almost no repositories for Wireshark profiles.
In fact, I just attended a Wireshark related Webinar where one of the presenters said (and I quote exactly) they "do not like sharing profiles", because, they said "you don't know what things have been set in the profiles that you yourself have not created"!
Sounds to me like always starting from scratch is a great way to dive up consulting hours and limiting knowledge share.
I mean, I get the point, someone could sneak something into the profile that is bad. So you should be wary of this. You should unzip a zipped profile and make sure it only contains TXT files. That said, this is no reason to not share profiles. It's like saying you should not use open source software because you never know who inserted something into the code. Possible, but in the long run, as long as you are watchful and wary, this thinking is ridiculous.
We try to state below what changes we have made, additions to, etc. the profiles we offer. WE DO NOT POST ANYTHING WE WOULD CONSIDER SHADY.
To use any of the profiles here, simply download the profile(s) you want, and unzip them into the Wireshark profiles directory.
If you do not see a "profiles" folder, then create one (all lower case).
We have always shared our profiles, but we have never opened up a place for others to share back! So after much consideration, we have decided to give this a try!
We have always had the position that it would be unsafe to simply open this up to anyone who wishes to upload anything. So if you wish to contribute a profile, or you modify/improve one of these profiles, please zip up the profile and email me (firstname.lastname@example.org)! I will post sent profiles here.
Also, feel free to browse our other Wireshark related articles and information here!
Click on the Title to get more information, or click on the download button to the right to simply download the ZIP