Wireshark: Difference between revisions

From SecurityTools
Starting point for WireShark. Still finding my legs.
 
m Tiny tidying-up change, add link to Udemy Wireshark course plus instructor's Twitter account.
 
(6 intermediate revisions by 2 users not shown)
Line 1: Line 1:
=== Description ===
[https://www.wireshark.org/ Wireshark] is a [[Free and Open-Source Software|free and open-source]] [[wikipedia:Packet_analyzer|network protocol analyzer]] that works on all major operating systems. Wireshark was originally named Ethereal, but changed its name in 2006 [https://www.wireshark.org/faq.html#q1.2 due to trademark issues]. The tool can be [https://www.wireshark.org/#download downloaded] from the official site, and copious [https://www.wireshark.org/docs/ documentation and tutorials are also available] there.
[https://www.wireshark.org/ Wireshark] is a [[Free and Open-Source Software|free and open-source]] [[wikipedia:Packet_analyzer|network protocol analyzer]] that works on all major operating systems. Wireshark was originally named Ethereal, but changed its name in 2006 [https://www.wireshark.org/faq.html#q1.2 due to trademark issues]. The tool can be [https://www.wireshark.org/#download downloaded] from the official site, and copious [https://www.wireshark.org/docs/ documentation and tutorials are also available] there.


For full functionality, Wireshark needs to be run in promiscuous mode. This requires root or administrator privileges, depending on the operating system. It can be run with normal user privileges, but this limits the tool to only sniffing packets to and from the host machine.
For full functionality, Wireshark needs to be run in promiscuous mode. This requires root or administrator privileges, depending on the operating system. It can be run with normal user privileges, but this limits the tool to only sniffing packets to and from the host machine.
=== Tool Type ===
* [[Network protocol analyzer]]
=== More Information ===
* The [https://www.wireshark.org/docs/ Official Wireshark documentation] website
* Udemy offers the [https://www.udemy.com/course/wireshark-ultimate-hands-on-course/ ultimate hands-on course] for learning Wireshark from tool expert [https://twitter.com/packetpioneer/ Chris Greer]
*Laura Chappell's [https://www.amazon.com/Wireshark-101-Essential-Analysis-Solution/dp/1893939758/?tag=securitytoo08-20 Wireshark 101: Essential Skills for Network Analysis - Second Edition] book
*[https://unit42.paloaltonetworks.com/wireshark-workshop-videos/ Unit 42 Wireshark workshop] video tutorials collection
* Lifewire [https://www.lifewire.com/wireshark-tutorial-4143298 Wireshark tutorial]
* [https://www.ictshore.com/wireshark/wireshark-filter-tutorial/ Wireshark filter tutorial]
*More sample packet captures than you can likely get through in a lifetime at [https://malware-traffic-analysis.net/ Malware Traffic Analysis]
*A treasure trove of [https://wiki.wireshark.org/SampleCaptures additional sample traffic captures] are available on the Wireshark wiki
*StationX giving us [https://www.stationx.net/wireshark-cheat-sheet/ a substantial Wireshark cheat sheet]


===Similar tools===
===Similar tools===

Latest revision as of 03:56, 24 September 2023

Description

Wireshark is a free and open-source network protocol analyzer that works on all major operating systems. Wireshark was originally named Ethereal, but changed its name in 2006 due to trademark issues. The tool can be downloaded from the official site, and copious documentation and tutorials are also available there.

For full functionality, Wireshark needs to be run in promiscuous mode. This requires root or administrator privileges, depending on the operating system. It can be run with normal user privileges, but this limits the tool to only sniffing packets to and from the host machine.

Tool Type

More Information

Similar tools