Wireshark app icon

Browsers and internet

Wireshark

Capture and inspect network traffic on Windows with detailed protocol decoding, display filters, stream following and a command-line companion.

WindowsmacOSLinuxGPL-2.0

See what is actually crossing the network

Wireshark records network traffic and decodes it into readable protocol fields. It is the reference tool for the job: it speaks hundreds of protocols, understands the layers between them, and can reconstruct a conversation from individual packets. Administrators use it to find why a connection fails, developers to check what their software really sends, and security teams to examine traffic during incident response.

Capturing and reading a trace

A capture starts by selecting an interface and, optionally, a capture filter that limits what is recorded at all, which matters on busy links because every packet consumes memory and disk. Once a trace is running, packets appear in a list with a summary column, a decoded detail tree for the selected packet and the raw bytes below it. Display filters then narrow the view without discarding data: show only traffic to one host, only DNS queries, only TCP resets, or only one conversation. Useful operations include following a TCP, UDP or HTTP stream to read a whole exchange as text, exporting objects such as images and documents transferred over HTTP, and building statistics about conversations, endpoints and protocol distribution. Profiles let you keep separate layouts and filters for different kinds of work.

Decoding encrypted traffic and scripting

TLS traffic can be decrypted when the keys are available, either by supplying the server's private key for older key-exchange methods or, more reliably, by pointing Wireshark at a key log file produced by the browser for that session. The command-line companion tshark performs captures and extractions without the graphical interface, and the capture and edit utilities handle interface listing, file merging and conversion, which makes the toolkit usable in scripts and on machines without a desktop session. Live capture on Windows needs the Npcap driver, offered during installation, and requires administrative privileges; USB capture is a separate optional component.

Practical limits and resource costs

Wireshark only sees traffic that reaches the machine's network adapter. On a switched network that means your own traffic unless the switch is configured to mirror a port or a tap is placed in the path, so "sniff the whole office" is not something it can do by itself. Wireless captures depend on adapter and driver support for monitor mode. Long captures grow quickly and can exhaust memory, so ring buffers and capture filters are normal practice rather than advanced options. Files that contain credentials, personal data or proprietary payloads deserve the same handling as any other sensitive record, and capturing traffic that is not yours may require authorisation depending on where you are.

When a simpler tool will do

For a quick check of connectivity, ordinary command-line tools answer faster. For continuous monitoring and alerting, a dedicated network monitoring system is more appropriate than a desktop analyser. Wireshark is the right choice when the question is "what exactly is on the wire", and it is hard to beat for one-off deep inspection.

Best for
Network and system administrators, developers and security analysts who need to read real traffic, troubleshoot protocol problems or verify what an application sends.
Good to know
Live capture needs the Npcap driver and administrator rights. A switched network only delivers your own traffic unless port mirroring or a tap is in place, and captures can contain sensitive data.

Wireshark records network traffic and decodes it into fields you can actually read.

How to get started

  1. Install Wireshark and accept the Npcap driver, which live capture on Windows depends on.
  2. Start it as administrator, pick the interface carrying the traffic you care about, and leave the capture filter empty for the first run.
  3. Reproduce the problem for a few seconds, then stop the capture so the file stays small.
  4. Use a display filter to narrow the list, for example to one host address or one protocol.
  5. Right-click a packet and follow the TCP or HTTP stream to read the whole exchange.
  6. Save the trace to a file before closing, and remember that it may contain credentials or personal data.

Questions & answers

Why do I only see my own traffic?

On a switched network the adapter receives only traffic addressed to it. Seeing other hosts requires a mirrored port or a network tap.

Can Wireshark decrypt HTTPS?

Yes, if you can supply the session keys, for example a key log file written by the browser you are testing. Without keys, the payload stays encrypted.

Does it need administrator rights?

Live capture does, because it puts the adapter into promiscuous mode and installs the capture driver. Reading a saved file does not.

More in browsers and internet

View category