EMZETT.
Login

Wireshark

In short: The best-known graphical open-source tool for network analysis — a sniffer with detailed protocol decoding and filtering capabilities.

In more detail: Wireshark records the traffic of a network interface and displays every single packet broken down readably with all protocol layers (Ethernet, IP, TCP/UDP, application layer). Display filters (e.g. tcp.port == 443) let you specifically filter out the traffic you’re interested in. Used both for troubleshooting network problems and for security analysis — encrypted traffic (TLS) is visible, but not readable in plain text without the matching key.

In Depth

A typical Wireshark display filter combines protocol, port and further conditions to filter out exactly the interesting packets from thousands of recorded ones:

tcp.port == 443                  # HTTPS traffic only
ip.addr == 192.168.1.50          # only traffic to/from a specific IP
tcp.flags.syn == 1               # only SYN packets (new connection attempts)
http.request.method == "POST"    # only HTTP POST requests

Wireshark shows every recorded packet in a layered view that corresponds exactly to the OSI model — you can click your way from the raw Ethernet frame through the IP header and the TCP/UDP header down to the actual application data payload, and inspect every single layer individually, including all header fields (sequence numbers, flags, checksums). This makes it the standard tool for really understanding network problems at the protocol level, rather than just seeing symptoms (“the connection is slow”).

For security-relevant analysis, Wireshark is used, for example, to inspect TLS handshakes (which cipher suite was negotiated, is the certificate plausible), detect suspicious connection patterns (an infected device repeatedly establishing connections to an unknown IP), or verify your own attacks as part of penetration tests. Important: Wireshark itself doesn’t actively interfere with traffic, it only reads passively — for active manipulation (e.g. ARP spoofing, to be able to see other people’s traffic at all), you need other, additional tools.

Promiscuous mode and switched networks

For Wireshark to see other people’s traffic at all (not just traffic explicitly addressed to your own device), the network card has to run in so-called “promiscuous mode” — this makes it process ALL packets that physically arrive at it, instead of only processing those meant for its own MAC address and discarding the rest. On modern switched networks (unlike old hub networks), a single device by default only sees its own traffic anyway, because a switch specifically forwards packets only to the matching port — to see other people’s traffic anyway, you need either physical access to a specially configured “mirror port” on the switch, or an active technique like ARP spoofing.

Wireshark in an educational context

Wireshark is often used in IT training to learn network protocols not just theoretically but concretely, visibly: a trainee can watch live how a TCP handshake actually happens (SYN, SYN-ACK, ACK as individually visible packets), how a DNS query is structured, or how a DHCP device gets assigned an IP address when connecting (the DORA sequence) — abstract protocol descriptions from the textbook thereby become concretely observable, real data packets.

Alternative tools

Besides Wireshark, there are other widespread tools for similar purposes: tcpdump is the text-based counterpart for the command line, particularly useful on servers without a graphical interface, or for producing recordings remotely that are then opened locally in Wireshark. tshark is Wireshark’s own command-line variant with the same decoding capabilities, useful for automated scripts. For specialised purposes there are also tools like nmap (port scanning instead of pure recording) or mitmproxy (specifically for HTTPS traffic, with the ability to actively manipulate requests instead of just reading passively) — Wireshark, however, remains the most versatile tool for general, cross-protocol analysis.

See also: Sniffer