Leanpub Header

Skip to main content

Practical Wireshark

Practical Wireshark

A capture that's too big, a complaint that's too vague: this book teaches you to get from there to the packets that explain it. Twenty chapters and 80 exercises on real captures take you from your first capture to TLS decryption, scan detection and your own Lua dissector, with the output of commands run in the lab cited on the page so you can check it yourself.

Minimum price

$19.00

$29.00

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
WEB
APP
Discussion Forum
About

About

About the Book

Most Wireshark books teach the interface. This one teaches you to answer questions with it.

Practical Wireshark starts where every investigation starts, with a capture that's too big and a complaint that's too vague, and works toward the packets that explain it. You'll learn where to put the sniffer so it actually sees the traffic, how to capture without drowning, and how to write display filters that find the one conversation that matters. From there the book moves through the protocols you meet every day (ARP, DHCP, DNS, TCP, HTTP/2 and HTTP/3, SIP and RTP), then into harder ground: decrypting TLS and QUIC with session keys, following a Wi-Fi join in monitor mode, and pinning a slow page load to a specific stage of the path.

The security chapters cover what an analyst actually looks for: port scans and how to tell their types apart, malware beacons and their timing, suspicious DNS, and credentials leaking in cleartext. The last part turns everything into automation with tshark one-liners, scheduled reports, Python with pyshark, and a Lua dissector for a protocol Wireshark has never seen.

The book is built on real captures. It works from a set of public sample captures, and where a chapter shows a tool's output from those files, the run is cited like any other source, so you can reproduce it on your own machine. Each of the 20 chapters ends with exercises, and an appendix gives a worked answer to every one, with the command to run.

What's inside

- 20 chapters in six parts, from first capture to traffic forensics

- 80 hands-on exercises with fully worked answers

- Display filter and capture filter quick reference

- Command-line toolkit reference for tshark, dumpcap, capinfos, editcap and mergecap

- Written for Wireshark 4.6, including its current filter semantics

Author

About the Author

Ground Truth Books

Ground Truth Books publishes practical technical books on computer science, IT tools, data science, machine learning, software engineering and AI.

The name comes from machine learning, where "ground truth" means the real, verified answers you check a model against. That's how these books are made. They're researched and drafted with AI assistance, and then checked against reality. Examples are run against real captures and data in a lab, and those runs are cited like any other source, so you can see which output came straight from the tool. Every claim is cited to its source, with official documentation, specifications and source code preferred over blog posts.

Each book is built around doing the work. Chapters end with exercises, and an appendix gives worked answers you can reproduce on your own machine, using the same freely available data and captures.

Books are updated when the tools change. If you find an error, please report it: a corrected edition is free for every reader, which is one of the best things about Leanpub.

Contents

Table of Contents

Part I: Foundations of Capture

Your First Capture: Installing Wireshark and Building Your Workspace

  1. Installing Wireshark on Windows, macOS, and Linux
  2. Choosing a capture interface
  3. The three panes
  4. Columns that show what matters
  5. Filtering your first capture
  6. Saving and reopening captures
  7. Configuration profiles
  8. Exercises

Where to Put the Sniffer: Hubs, SPAN, TAPs, Virtual Switches, and Remote Capture

  1. The capture point decides what you see
  2. Why a laptop on a switch port sees only its own traffic
  3. SPAN and port mirroring
  4. Network TAPs
  5. TAP versus SPAN
  6. Capturing in virtualized and cloud environments
  7. Remote capture over SSH with sshdump
  8. Remote capture with rpcapd
  9. Permission, privacy, and the ethics of passive capture
  10. Exercises

Capturing the Right Traffic and Saving It Well: Capture Filters, pcapng, dumpcap, and Ring Buffers

  1. A Collection Plan Before a Single Frame
  2. Capture filters vs. display filters
  3. Berkeley Packet Filter syntax
  4. Recipes and where to type them
  5. What pcapng adds
  6. dumpcap for headless capture
  7. Ring buffers and file-size limits
  8. Performance and very large captures
  9. Exercises

Managing Capture Files at Scale: capinfos, editcap, and mergecap

  1. capinfos
  2. editcap: extracting packet ranges and dropping packets
  3. editcap: deduplication and timestamp adjustment
  4. mergecap: combining captures and controlling the output order
  5. A triage workflow: from a messy capture folder to a single clean file
  6. Verifying that edits did what you intended
  7. Exercises
  8. Part II: The Filter Language and the Command Line

The Display Filter Language: Syntax, Operators, and the Field Reference

  1. Fields, protocols, and the reference
  2. Comparison operators
  3. Logical operators and parentheses
  4. contains and matches
  5. Values: addresses, ports, flags, strings
  6. The GUI path and saved filters
  7. Idioms: host, conversation, failures
  8. Exercises

Making Traffic Stand Out: Coloring Rules, Following Streams, and Time References

  1. Reading the default coloring rules
  2. Writing your own coloring rules and ordering their priority
  3. Following streams to rebuild conversations
  4. Using follow-stream views to spot and extract payloads
  5. Time references
  6. Bookmarks and navigation for long captures
  7. Exercises

tshark: The Terminal Wireshark

  1. tshark basics
  2. Capture and display filters
  3. Printing fields with -T fields and -e
  4. Reading only a range of packets
  5. GUI features on the command line
  6. Stream reconstruction and export from the command line
  7. Real-world tshark one-liners for fast triage
  8. Performance on very large captures
  9. One pipeline, end to end
  10. Exercises
  11. Part III: Everyday Protocols

Getting Online: ARP, DHCP, and DNS

  1. The boot packet story
  2. ARP request/reply and variants
  3. The DORA exchange and lease failures
  4. DNS anatomy and correlation
  5. Filters for ARP, DHCP, and DNS
  6. Triage: “I can’t reach the website”
  7. Exercises

TCP Under the Microscope: Handshakes, Retransmissions, and Sequence Analysis

  1. The Three-Way Handshake as Captured
  2. Sequence and Acknowledgment Numbers
  3. Retransmissions: What They Mean and How to Count Them
  4. Duplicate ACKs and Fast Retransmit
  5. Zero Window and Window Updates
  6. The Expert-Info View
  7. Attributing the Cause: Client, Network, or Server
  8. Exercises

Modern Web Protocols: HTTP/2 and HTTP/3

  1. From HTTP/1.1 to HTTP/2
  2. Reading the HTTP/2 dissection
  3. Isolating a single stream
  4. HTTP/3 on QUIC
  5. QUIC dissection with and without keys
  6. When you need a key log
  7. Exercises

Voice and Video: SIP, RTP, and VoIP Analysis

  1. SIP call setup
  2. Signaling and media in one capture
  3. RTP basics
  4. The RTP stream analysis window
  5. VoIP Calls
  6. A trace walk-through
  7. Exercises
  8. Part IV: Encrypted, Wireless, and Slow Traffic

Decrypting TLS and QUIC with Session Keys

  1. What TLS 1.2 and 1.3 hide
  2. How SSLKEYLOGFILE works
  3. Generating a key log and pointing Wireshark at it
  4. Decrypting TLS captures
  5. Decrypting QUIC and HTTP/3
  6. Verifying decryption
  7. Exercises

Capturing Wi-Fi in Monitor Mode

  1. Adapters, drivers, and monitor mode
  2. Channel hopping
  3. 802.11 frame types
  4. Beacons, probes, and association
  5. Columns, filters, and expert info
  6. Practice: Reading a join
  7. Legal and privacy reality
  8. Exercises

Finding the Bottleneck: Expert Info, I/O Graphs, and TCP Stream Graphs

  1. The expert info window
  2. From symptom to hypothesis
  3. I/O graphs
  4. TCP stream graphs
  5. Network delay or application delay
  6. Complete case: ‘the app is slow’, start to finish
  7. Exercises
  8. Part V: Security Use Cases

Detecting Reconnaissance and Port Scans

  1. SYN scan anatomy
  2. Incomplete SYN handshake
  3. The conversations view
  4. Recognizing nmap probes
  5. False positives
  6. From scan to attribution
  7. Exercises

Malware Beacons and Call-Home Patterns

  1. What a Beacon Is
  2. Finding Beacon Candidates with tshark Summaries and Flow Statistics
  3. Measuring Beacon Interval and Interval Jitter
  4. DNS and HTTP Beacons versus HTTPS Beacons
  5. Beacon False Positives
  6. Practice: Hunting a Beacon in a Malware-Traffic-Analysis Capture
  7. Exercises

Suspicious DNS and Credential Leaks in Real Traces

  1. DNS as a channel: how tunneling works and what it looks like in queries
  2. Measuring query entropy and spotting long, suspicious labels in captures
  3. Finding plaintext credentials: follow-stream across HTTP, FTP, Telnet, and SMTP
  4. Exporting objects to pull exfiltrated files out of a pcap
  5. A forensics-style walkthrough: from odd DNS traffic to a remote shell
  6. Reporting what you found and what it means
  7. Exercises
  8. Part VI: Automation and Extension

Extracting Fields and Automating Analysis with tshark

  1. The one-liner
  2. -T fields, -e, and -E: building exactly the rows you need
  3. Summarizing traffic with shell pipelines
  4. Pulling fields from HTTP, DNS, and TLS conversations
  5. Looping over many files and scheduling jobs
  6. Why tshark fails in cron
  7. A canned daily traffic report you can ship today
  8. Exercises

Driving Captures and Analysis with Python: pyshark

  1. Installing pyshark
  2. Reading pcap and pcapng files
  3. Layers and fields
  4. Live capture
  5. Scheduling pyshark captures with cron
  6. Working example: flag suspicious DNS queries
  7. Exercises

Writing Lua Dissectors for Custom Protocols

  1. When you need a dissector
  2. Dissector anatomy
  3. Parsing the header
  4. Subtrees, columns, and expert annotations
  5. Port-based registration versus heuristic dissection
  6. Testing against a real capture
  7. Exercises

Appendix A: Display Filter and Capture Filter Quick Reference

  1. The Two Filter Families
  2. Display Filter Language
  3. Ready-Made Display Filters
  4. Capture Filters (BPF)
  5. Converting Between Families

Appendix B: Command-Line Toolkit Reference

  1. The Tools and Their Jobs
  2. Common Behaviors
  3. tshark: Capture and Read
  4. dumpcap
  5. capinfos
  6. editcap
  7. mergecap
  8. Companion Tools
  9. File Locations and Automation Notes

Appendix C: Where to Find Practice Captures

  1. Generate Your Own Traffic
  2. Official Wireshark Sample Captures
  3. Training Collections with Answer Keys
  4. Malware and Intrusion Traffic
  5. CTF and Competition Captures
  6. Broad and Benchmark Captures
  7. Finding Captures by Search
  8. Verify Before You Analyze

Appendix D: Lab Captures and Answers to the Exercises

  1. Chapter 1: Your First Capture: Installing Wireshark and Building Your Workspace
  2. Chapter 2: Where to Put the Sniffer: Hubs, SPAN, TAPs, Virtual Switches, and Remote Capture
  3. Chapter 3: Capturing the Right Traffic and Saving It Well: Capture Filters, pcapng, dumpcap, and Ring Buffers
  4. Chapter 4: Managing Capture Files at Scale: capinfos, editcap, and mergecap
  5. Chapter 5: The Display Filter Language: Syntax, Operators, and the Field Reference
  6. Chapter 6: Making Traffic Stand Out: Coloring Rules, Following Streams, and Time References
  7. Chapter 7: tshark: The Terminal Wireshark
  8. Chapter 8: Getting Online: ARP, DHCP, and DNS
  9. Chapter 9: TCP Under the Microscope: Handshakes, Retransmissions, and Sequence Analysis
  10. Chapter 10: Modern Web Protocols: HTTP/2 and HTTP/3
  11. Chapter 11: Voice and Video: SIP, RTP, and VoIP Analysis
  12. Chapter 12: Decrypting TLS and QUIC with Session Keys
  13. Chapter 13: Capturing Wi-Fi in Monitor Mode
  14. Chapter 14: Finding the Bottleneck: Expert Info, I/O Graphs, and TCP Stream Graphs
  15. Chapter 15: Detecting Reconnaissance and Port Scans
  16. Chapter 16: Malware Beacons and Call-Home Patterns
  17. Chapter 17: Suspicious DNS and Credential Leaks in Real Traces
  18. Chapter 18: Extracting Fields and Automating Analysis with tshark
  19. Chapter 19: Driving Captures and Analysis with Python: pyshark
  20. Chapter 20: Writing Lua Dissectors for Custom Protocols

Glossary

References

Get the free sample chapters

Click the buttons to get the free sample in PDF or EPUB, or read the sample online here

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub