Wireshark

https://mega.nz/#F!oWJwVSRC!SWYzxOzE2QDaTU50yrKrKw

Wireshark is a GUI based protocol analyzer. It works on live traffic and PCAP files.

When you first launch Wireshark a welcome screen similar to the one shown above should be visible, containing a list of available network connections on your current device. In this example, you'll notice that the following connection types are shown: Bluetooth Network Connection, Ethernet, VirtualBox Host-Only Network, Wi-Fi. Displayed to the right of each is an EKG-style line graph that represents live traffic on that respective network.

To begin capturing packets, first select one or more of these networks by clicking on your choice(s) and using the Shift or Ctrl keys if you'd like to record data from multiple networks simultaneously. Once a connection type is selected for capturing purposes, its background will be shaded in either blue or gray. Click on Capture from the main menu, located towards the top of the Wireshark interface. When the drop-down menu appears, select the Start option.

You can also initiate packet capturing via one of the following shortcuts.

  • Keyboard: Press Ctrl + E
  • Mouse: To begin capturing packets from one particular network, simply double-click on its name
  • Toolbar: Click on the blue shark fin button, located on the far left-hand side of the Wireshark toolbar

The live capture process will now begin, with packet details displayed in the Wireshark window as they are recorded. Perform one of the actions below to stop capturing.

  • Keyboard: Press Ctrl + E
  • Toolbar: Click on the red stop button, located next to the shark fin on the Wireshark toolbar

results matching ""

    No results matching ""