Forensics
Wireshark / tshark
World-class packet capture and protocol analysis tool.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Analyzing network traffic, protocols, and evidence PCAP files.
How
Capture or open PCAP; filter (display filters); follow streams.
Why
Network literacy is non-negotiable in cyber careers.
Commands & usage
wireshark
tshark -i eth0 -w capture.pcap
tshark -r capture.pcap -Y 'http.request'
tshark -r capture.pcap -z follow,tcp,ascii,0
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Comparisons
Tags
Related in Forensics
Volatility 3
Memory forensics framework for RAM dumps.
Autopsy
GUI digital forensics platform on The Sleuth Kit.
The Sleuth Kit
CLI tools for disk image forensic analysis.
tcpdump
CLI packet capture utility.
ExifTool
Read/write metadata in files (images, docs, etc.).
steghide / zsteg / steghide tools
Steganography detection and extraction tools for CTFs and investigations.