โ† All cheat sheets

WIRESHARK

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

CAPTURE FILTERS (BPF Syntax)#

# Applied BEFORE capture starts

host 192.168.1.1                 # Traffic to/from host
src host 192.168.1.1             # Source host
dst host 192.168.1.1             # Destination host
net 192.168.1.0/24               # Traffic to/from network
port 80                          # Traffic on port 80
src port 80                      # Source port 80
dst port 80                      # Destination port 80
tcp                              # TCP traffic only
udp                              # UDP traffic only
icmp                             # ICMP traffic only
tcp port 80                      # TCP port 80
not arp                          # Exclude ARP
host 192.168.1.1 and port 80     # Combined filter

DISPLAY FILTERS#

# Applied AFTER capture (in filter bar)

# IP Filters
ip.addr == 192.168.1.1           # IP address (src or dst)
ip.src == 192.168.1.1            # Source IP
ip.dst == 192.168.1.1            # Destination IP
ip.addr == 192.168.1.0/24        # Subnet
ip.ttl == 64                     # TTL value
ip.version == 4                  # IPv4 only
ipv6                             # IPv6 traffic

# TCP Filters
tcp                              # All TCP
tcp.port == 80                   # TCP port 80
tcp.srcport == 80                # TCP source port
tcp.dstport == 80                # TCP destination port
tcp.flags.syn == 1               # SYN packets
tcp.flags.ack == 1               # ACK packets
tcp.flags.fin == 1               # FIN packets
tcp.flags.rst == 1               # RST packets
tcp.flags.push == 1              # PSH packets
tcp.analysis.retransmission      # Retransmissions
tcp.analysis.duplicate_ack       # Duplicate ACKs
tcp.analysis.zero_window         # Zero window
tcp.stream == 5                  # TCP stream 5

# UDP Filters
udp                              # All UDP
udp.port == 53                   # UDP port 53
udp.srcport == 53                # UDP source port
udp.length > 100                 # UDP length > 100

# HTTP Filters
http                             # All HTTP
http.request                     # HTTP requests
http.response                    # HTTP responses
http.request.method == "GET"     # GET requests
http.request.method == "POST"    # POST requests
http.host == "example.com"       # Specific host
http.request.uri contains "/api" # URI contains
http.response.code == 200        # Response code
http.response.code >= 400        # Error responses
http.content_type contains "json"# Content type
http.user_agent contains "curl"  # User agent

# DNS Filters
dns                              # All DNS
dns.qry.name == "example.com"    # Query name
dns.qry.type == 1                # A record queries
dns.qry.type == 28               # AAAA record
dns.flags.response == 1          # DNS responses
dns.count.answers > 0            # Has answers

# TLS/SSL Filters
tls                              # All TLS
ssl                              # All SSL
tls.handshake                    # TLS handshake
tls.handshake.type == 1          # Client Hello
tls.handshake.type == 2          # Server Hello
tls.record.version == 0x0303     # TLS 1.2
ssl.handshake.ciphersuite        # Cipher suites

# ICMP Filters
icmp                             # All ICMP
icmp.type == 8                   # Echo request (ping)
icmp.type == 0                   # Echo reply
icmp.type == 3                   # Destination unreachable

# SMB Filters
smb                              # All SMB
smb2                             # SMB2/3
smb.file                         # File operations

# ARP Filters
arp                              # All ARP
arp.opcode == 1                  # ARP requests
arp.opcode == 2                  # ARP replies

# Logical Operators
and / &&                         # AND
or / ||                          # OR
not / !                          # NOT
eq / ==                          # Equals
ne / !=                          # Not equals
gt / >                           # Greater than
lt / <                           # Less than
ge / >=                          # Greater or equal
le / <=                          # Less or equal
contains                         # Contains string
matches                          # Regex match

# Combined Examples
ip.addr == 192.168.1.1 and tcp.port == 80
http and (ip.src == 192.168.1.1 or ip.dst == 192.168.1.1)
tcp.flags.syn == 1 and tcp.flags.ack == 0
dns and not dns.flags.response
http.request.method == "POST" and http.host == "api.example.com"
frame.time >= "2024-01-01" and frame.time <= "2024-01-31"

FINDING SPECIFIC TRAFFIC#

# Login attempts
http.request.method == "POST" and (http.request.uri contains "login" or http.request.uri contains "auth")

# Suspicious DNS
dns.qry.name contains "suspicious" or dns.qry.type == 16

# Large transfers
tcp.len > 1000

# Failed connections
tcp.flags.rst == 1

# Cleartext passwords
http.request.method == "POST" and http.request.uri contains "password"

KEYBOARD SHORTCUTS#

Ctrl+E                           # Start/Stop capture
Ctrl+K                           # Capture options
Ctrl+F                           # Find packet
Ctrl+G                           # Go to packet
Ctrl+N                           # Next packet
Ctrl+B                           # Previous packet
Ctrl+Shift+F                     # Find next
Ctrl+M                           # Mark packet
Ctrl+Alt+C                       # Clear marks
Space                            # Toggle packet detail
Tab                              # Next pane

TSHARK (Command Line)#

# Capture
tshark -i eth0                   # Capture on interface
tshark -i eth0 -w capture.pcap   # Save to file
tshark -r capture.pcap           # Read from file
tshark -c 100                    # Capture 100 packets

# Filters
tshark -f "port 80"              # Capture filter
tshark -Y "http"                 # Display filter
tshark -R "http.request"         # Read filter (deprecated)

# Output
tshark -T fields -e ip.src -e ip.dst    # Specific fields
tshark -T json                   # JSON output
tshark -T pdml                   # XML output

# Statistics
tshark -qz io,stat,1             # I/O statistics
tshark -qz conv,tcp              # TCP conversations
tshark -qz http,tree             # HTTP statistics

USEFUL STATISTICS#

Statistics > Capture File Properties
Statistics > Protocol Hierarchy
Statistics > Conversations
Statistics > Endpoints
Statistics > HTTP > Requests
Statistics > Flow Graph
Analyze > Follow > TCP Stream
Analyze > Expert Information

COMMON ANALYSIS TASKS#

# Follow TCP stream
Right-click packet > Follow > TCP Stream

# Extract files from HTTP
File > Export Objects > HTTP

# Find credentials
Edit > Find Packet > String > "password"

# Analyze TLS handshake
Filter: tls.handshake

# Check for DNS tunneling
Filter: dns and dns.qry.name matches ".*\\..*\\..*\\..*"