Skip to main content

Capture

CLI (tshark)


Display Filters

By Protocol

By IP

By Port

By Flags

Combine


Capture Filters (BPF)

Applied before capture (less CPU):

Follow Streams

Right-click packet → Follow → TCP/UDP/HTTP Stream.

tshark


Credential Extraction

HTTP Auth

FTP

Telnet

Follow TCP stream to see plaintext credentials.

SMB

SMTP


Export Objects

File → Export Objects → HTTP/SMB/FTP/TFTP.

tshark


Statistics

  • Statistics → Endpoints (top talkers)
  • Statistics → Conversations (who talks to whom)
  • Statistics → Protocol Hierarchy (protocol breakdown)
  • Statistics → I/O Graphs (traffic over time)

Useful Filters


tshark One-Liners


Quick Reference