All tools

Forensics

Wireshark / tshark

World-class packet capture and protocol analysis tool.

beginner
Windows
Linux
macOS
Scanning
Forensics
Enumeration

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Analyzing network traffic, protocols, and evidence PCAP files.

How

Capture or open PCAP; filter (display filters); follow streams.

Why

Network literacy is non-negotiable in cyber careers.

Commands & usage

wireshark
tshark -i eth0 -w capture.pcap
tshark -r capture.pcap -Y 'http.request'
tshark -r capture.pcap -z follow,tcp,ascii,0

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

pcap
network
essential

Related in Forensics