Wireshark

Content that refers to the Wireshark packet analysis tool.

What Can Wireshark Really Tell You About an Encrypted Signal Conversation?

Post Views: 281 Signal has a well-earned reputation as a secure messaging application. Messages, voice calls, video calls, files, and other Signal-to-Signal communications are protected using end-to-end encryption. Signal states that message and call contents cannot be accessed by Signal or other third parties because the communications are always end-to-end encrypted. So that raises an

What Can Wireshark Really Tell You About an Encrypted Signal Conversation? Read More »

, , , , ,

Why Your Wireshark Filter May Not Mean What You Think It Means

Post Views: 149 Wireshark display filters can look deceptively simple. For example: tcp.port > 1024 seems obvious. But a TCP packet normally has two port values: a source port and a destination port. That means Wireshark may be evaluating more than one value when you write a filter. Consider: This packet satisfies: tcp.port > 1024

Why Your Wireshark Filter May Not Mean What You Think It Means Read More »

, ,

10 Wireshark Display Filter Functions You’re Probably Not Using

Post Views: 221 Most Wireshark users learn display filters by comparing a field to a value: ip.addr == 192.168.1.10 tcp.port == 443 dns.qry.name contains “example” But modern Wireshark display filters can do much more than simple comparisons. The filter language includes functions that can measure field lengths, count repeated fields, manipulate text, compare values, and

10 Wireshark Display Filter Functions You’re Probably Not Using Read More »

, , ,

Synchronize Two Wireshark Captures by Correcting Clock Drift

Post Views: 340 I discussed correlating packet captures from multiple capture points last week. In that post, one of the things I promised was to dive deeper into clock offsets and clock drift. When troubleshooting from more than one capture point, it is common to compare traffic from places such as: Before those captures can

Synchronize Two Wireshark Captures by Correcting Clock Drift Read More »

, , , ,

Wireshark’s Slice Operator: Search Exact Bytes Without Writing a Dissector

Post Views: 385 Wireshark gives us thousands of protocol fields to filter on: But what happens when the exact information you want isn’t exposed as a field? That is where Wireshark’s Slice Operator becomes extremely useful. A slice lets you select specific bytes from a field, payload, protocol, or even the captured frame itself. For

Wireshark’s Slice Operator: Search Exact Bytes Without Writing a Dissector Read More »

, , , ,

Correlating Multiple Wireshark Captures: Follow the Same Packet Across the Network

Post Views: 407 So many times I have watched YouTube videos and read articles that jump right into Wireshark troubleshooting of multiple captures of a network conversation or event from multiple points in the network. To me, that can be unnecessarily overwhelming to those learning packet capture. In many videos, it never becomes clear why

Correlating Multiple Wireshark Captures: Follow the Same Packet Across the Network Read More »

, ,

Turn Wireshark Columns into Calculated Network Analytics

Post Views: 274 Most Wireshark users eventually discover Custom Columns. Instead of being limited to the standard Source, Destination, Protocol, Length, and Info columns, you can add useful fields such as: tcp.stream tcp.analysis.ack_rtt dns.qry.name vlan.id That alone can make packet analysis much easier. But in newer versions of Wireshark, Custom Columns can do much more

Turn Wireshark Columns into Calculated Network Analytics Read More »

, , ,

The Wireshark # Operator: Filter the Inner vs. Outer IP Header

Post Views: 633 Most Wireshark filters assume there is only one IP header in a packet. For example: ip.src == 10.1.1.10 works perfectly well in ordinary traffic. But what happens when the packet contains more than one IP header? That is common with technologies such as: A tunneled packet might look like this structure: Now

The Wireshark # Operator: Filter the Inner vs. Outer IP Header Read More »

, , , , ,

Where can I get PCAP Packet Captures for Learning and Exploration?

Post Views: 6,934 I am often asked this question of where to access PCAP or PCAP-NG files so that folks can explore packet captures using Wireshark.  I have always provided these resources in my Wireshark classes at the Online School, but thought I should also just list them here for public consumption. Before you click!

Where can I get PCAP Packet Captures for Learning and Exploration? Read More »

, , , ,

The Wireshark $ Operator: Build Filters Around the Packet You Click

Post Views: 852 Most Wireshark display filters use values that you type manually. For example: ip.addr == 192.168.1.100 or: tcp.stream == 14 But Wireshark has a lesser-known capability that lets you build a filter using values from the packet you currently have selected. That capability is called a field reference, and it uses the $

The Wireshark $ Operator: Build Filters Around the Packet You Click Read More »

, , ,

The Best Auto Switch Filters for Wireshark Profiles

Post Views: 387 One of the cooler features added to recent versions of Wireshark is the ability to automatically select a Configuration Profile when you open a capture file. I covered how to configure this feature in my earlier article, Automatically Switch Configuration Profiles in Wireshark. Since then, I have spent more time thinking about

The Best Auto Switch Filters for Wireshark Profiles Read More »

, ,

Our BGP Lab Series is Up

Post Views: 329 Network Engineers and folks learning networking – my BGP Lab series is now available – you will find them here. There are three Labs that include GNS3 topologies, and PCAPS to emulate and capture these awesome labs. Starting with Basic, then looking at Multihop eBGP, then examining the protocol with Wireshark, then

Our BGP Lab Series is Up Read More »

, , , , , , , , , ,

OSPF Lab Series Now Available

Post Views: 409 Network Engineers and folks learning networking – my OSPF Lab series is now available – you will find them here. There are three Labs that include GNS3 topologies, and PCAPS to emulate and capture these awesome labs: We have also begun our BGP series as well with new labs coming each week.

OSPF Lab Series Now Available Read More »

, , , , , ,

End-to-End Encryption: A Privacy Victory or a Networking Blind Spot?

Post Views: 657 TLS 1.3, QUIC, HTTP/3, encrypted DNS, and Encrypted Client Hello increasingly conceal application and transport information that network operators traditionally used for troubleshooting, security inspection, filtering, performance optimization, and policy enforcement. Here is a little reference chart: This produces two defensible but conflicting positions: For most of the Internet’s history, and certainly

End-to-End Encryption: A Privacy Victory or a Networking Blind Spot? Read More »

, , , , , , , ,
Scroll to Top