Загрузка...

tshark Tutorials | Wireshark CLI for Packet Capture and Analysis

Meet tshark — the command-line version of Wireshark that lets you capture and analyze packets directly in your terminal. ⚡ No GUI, no heavy load, just fast and scriptable network analysis.

🔹 Install → sudo apt install tshark
🔹 List interfaces → tshark -D
🔹 Capture packets → sudo tshark -i eth0
🔹 Save capture to file → sudo tshark -i eth0 -w traffic.pcap
🔹 Read from pcap → tshark -r traffic.pcap
🔹 Filter by protocol → tshark -i eth0 -f "tcp port 80"
🔹 Filter by display → tshark -i eth0 -Y "http.request"
🔹 Limit packets → tshark -i eth0 -c 10

💡 Blue Team Tip:

Use tshark in servers or headless environments where GUI tools aren’t available.

Perfect for incident response scripts and automated log pipelines.

Combine with grep / awk / scripts for powerful, automated threat hunting.

👉 Lightweight, scriptable, and perfect for SOC analysts, incident responders, and Blue Teamers.

#tshark #Wireshark #PacketSniffing #LinuxSecurity #BlueTeam #SOC #CyberSecurity #NetworkAnalysis

Видео tshark Tutorials | Wireshark CLI for Packet Capture and Analysis канала InfoSec Pandey
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять