WIRESHARK
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
CAPTURE FILTERS (BPF Syntax)#
# Applied BEFORE capture starts host 192.168.1.1 # Traffic to/from host src host 192.168.1.1 # Source host dst host 192.168.1.1 # Destination host net 192.168.1.0/24 # Traffic to/from network port 80 # Traffic on port 80 src port 80 # Source port 80 dst port 80 # Destination port 80 tcp # TCP traffic only udp # UDP traffic only icmp # ICMP traffic only tcp port 80 # TCP port 80 not arp # Exclude ARP host 192.168.1.1 and port 80 # Combined filter
DISPLAY FILTERS#
# Applied AFTER capture (in filter bar) # IP Filters ip.addr == 192.168.1.1 # IP address (src or dst) ip.src == 192.168.1.1 # Source IP ip.dst == 192.168.1.1 # Destination IP ip.addr == 192.168.1.0/24 # Subnet ip.ttl == 64 # TTL value ip.version == 4 # IPv4 only ipv6 # IPv6 traffic # TCP Filters tcp # All TCP tcp.port == 80 # TCP port 80 tcp.srcport == 80 # TCP source port tcp.dstport == 80 # TCP destination port tcp.flags.syn == 1 # SYN packets tcp.flags.ack == 1 # ACK packets tcp.flags.fin == 1 # FIN packets tcp.flags.rst == 1 # RST packets tcp.flags.push == 1 # PSH packets tcp.analysis.retransmission # Retransmissions tcp.analysis.duplicate_ack # Duplicate ACKs tcp.analysis.zero_window # Zero window tcp.stream == 5 # TCP stream 5 # UDP Filters udp # All UDP udp.port == 53 # UDP port 53 udp.srcport == 53 # UDP source port udp.length > 100 # UDP length > 100 # HTTP Filters http # All HTTP http.request # HTTP requests http.response # HTTP responses http.request.method == "GET" # GET requests http.request.method == "POST" # POST requests http.host == "example.com" # Specific host http.request.uri contains "/api" # URI contains http.response.code == 200 # Response code http.response.code >= 400 # Error responses http.content_type contains "json"# Content type http.user_agent contains "curl" # User agent # DNS Filters dns # All DNS dns.qry.name == "example.com" # Query name dns.qry.type == 1 # A record queries dns.qry.type == 28 # AAAA record dns.flags.response == 1 # DNS responses dns.count.answers > 0 # Has answers # TLS/SSL Filters tls # All TLS ssl # All SSL tls.handshake # TLS handshake tls.handshake.type == 1 # Client Hello tls.handshake.type == 2 # Server Hello tls.record.version == 0x0303 # TLS 1.2 ssl.handshake.ciphersuite # Cipher suites # ICMP Filters icmp # All ICMP icmp.type == 8 # Echo request (ping) icmp.type == 0 # Echo reply icmp.type == 3 # Destination unreachable # SMB Filters smb # All SMB smb2 # SMB2/3 smb.file # File operations # ARP Filters arp # All ARP arp.opcode == 1 # ARP requests arp.opcode == 2 # ARP replies # Logical Operators and / && # AND or / || # OR not / ! # NOT eq / == # Equals ne / != # Not equals gt / > # Greater than lt / < # Less than ge / >= # Greater or equal le / <= # Less or equal contains # Contains string matches # Regex match # Combined Examples ip.addr == 192.168.1.1 and tcp.port == 80 http and (ip.src == 192.168.1.1 or ip.dst == 192.168.1.1) tcp.flags.syn == 1 and tcp.flags.ack == 0 dns and not dns.flags.response http.request.method == "POST" and http.host == "api.example.com" frame.time >= "2024-01-01" and frame.time <= "2024-01-31"
FINDING SPECIFIC TRAFFIC#
# Login attempts http.request.method == "POST" and (http.request.uri contains "login" or http.request.uri contains "auth") # Suspicious DNS dns.qry.name contains "suspicious" or dns.qry.type == 16 # Large transfers tcp.len > 1000 # Failed connections tcp.flags.rst == 1 # Cleartext passwords http.request.method == "POST" and http.request.uri contains "password"
KEYBOARD SHORTCUTS#
Ctrl+E # Start/Stop capture Ctrl+K # Capture options Ctrl+F # Find packet Ctrl+G # Go to packet Ctrl+N # Next packet Ctrl+B # Previous packet Ctrl+Shift+F # Find next Ctrl+M # Mark packet Ctrl+Alt+C # Clear marks Space # Toggle packet detail Tab # Next pane
TSHARK (Command Line)#
# Capture tshark -i eth0 # Capture on interface tshark -i eth0 -w capture.pcap # Save to file tshark -r capture.pcap # Read from file tshark -c 100 # Capture 100 packets # Filters tshark -f "port 80" # Capture filter tshark -Y "http" # Display filter tshark -R "http.request" # Read filter (deprecated) # Output tshark -T fields -e ip.src -e ip.dst # Specific fields tshark -T json # JSON output tshark -T pdml # XML output # Statistics tshark -qz io,stat,1 # I/O statistics tshark -qz conv,tcp # TCP conversations tshark -qz http,tree # HTTP statistics
USEFUL STATISTICS#
Statistics > Capture File Properties Statistics > Protocol Hierarchy Statistics > Conversations Statistics > Endpoints Statistics > HTTP > Requests Statistics > Flow Graph Analyze > Follow > TCP Stream Analyze > Expert Information
COMMON ANALYSIS TASKS#
# Follow TCP stream Right-click packet > Follow > TCP Stream # Extract files from HTTP File > Export Objects > HTTP # Find credentials Edit > Find Packet > String > "password" # Analyze TLS handshake Filter: tls.handshake # Check for DNS tunneling Filter: dns and dns.qry.name matches ".*\\..*\\..*\\..*"