Part I: Foundations of Capture
Your First Capture: Installing Wireshark and Building Your Workspace
- Installing Wireshark on Windows, macOS, and Linux
- Choosing a capture interface
- The three panes
- Columns that show what matters
- Filtering your first capture
- Saving and reopening captures
- Configuration profiles
- Exercises
Where to Put the Sniffer: Hubs, SPAN, TAPs, Virtual Switches, and Remote Capture
- The capture point decides what you see
- Why a laptop on a switch port sees only its own traffic
- SPAN and port mirroring
- Network TAPs
- TAP versus SPAN
- Capturing in virtualized and cloud environments
- Remote capture over SSH with sshdump
- Remote capture with rpcapd
- Permission, privacy, and the ethics of passive capture
- Exercises
Capturing the Right Traffic and Saving It Well: Capture Filters, pcapng, dumpcap, and Ring Buffers
- A Collection Plan Before a Single Frame
- Capture filters vs. display filters
- Berkeley Packet Filter syntax
- Recipes and where to type them
- What pcapng adds
- dumpcap for headless capture
- Ring buffers and file-size limits
- Performance and very large captures
- Exercises
Managing Capture Files at Scale: capinfos, editcap, and mergecap
- capinfos
- editcap: extracting packet ranges and dropping packets
- editcap: deduplication and timestamp adjustment
- mergecap: combining captures and controlling the output order
- A triage workflow: from a messy capture folder to a single clean file
- Verifying that edits did what you intended
- Exercises
- Part II: The Filter Language and the Command Line
The Display Filter Language: Syntax, Operators, and the Field Reference
- Fields, protocols, and the reference
- Comparison operators
- Logical operators and parentheses
- contains and matches
- Values: addresses, ports, flags, strings
- The GUI path and saved filters
- Idioms: host, conversation, failures
- Exercises
Making Traffic Stand Out: Coloring Rules, Following Streams, and Time References
- Reading the default coloring rules
- Writing your own coloring rules and ordering their priority
- Following streams to rebuild conversations
- Using follow-stream views to spot and extract payloads
- Time references
- Bookmarks and navigation for long captures
- Exercises
tshark: The Terminal Wireshark
- tshark basics
- Capture and display filters
- Printing fields with
-T fieldsand-e - Reading only a range of packets
- GUI features on the command line
- Stream reconstruction and export from the command line
- Real-world tshark one-liners for fast triage
- Performance on very large captures
- One pipeline, end to end
- Exercises
- Part III: Everyday Protocols
Getting Online: ARP, DHCP, and DNS
- The boot packet story
- ARP request/reply and variants
- The DORA exchange and lease failures
- DNS anatomy and correlation
- Filters for ARP, DHCP, and DNS
- Triage: “I can’t reach the website”
- Exercises
TCP Under the Microscope: Handshakes, Retransmissions, and Sequence Analysis
- The Three-Way Handshake as Captured
- Sequence and Acknowledgment Numbers
- Retransmissions: What They Mean and How to Count Them
- Duplicate ACKs and Fast Retransmit
- Zero Window and Window Updates
- The Expert-Info View
- Attributing the Cause: Client, Network, or Server
- Exercises
Modern Web Protocols: HTTP/2 and HTTP/3
- From HTTP/1.1 to HTTP/2
- Reading the HTTP/2 dissection
- Isolating a single stream
- HTTP/3 on QUIC
- QUIC dissection with and without keys
- When you need a key log
- Exercises
Voice and Video: SIP, RTP, and VoIP Analysis
- SIP call setup
- Signaling and media in one capture
- RTP basics
- The RTP stream analysis window
- VoIP Calls
- A trace walk-through
- Exercises
- Part IV: Encrypted, Wireless, and Slow Traffic
Decrypting TLS and QUIC with Session Keys
- What TLS 1.2 and 1.3 hide
- How SSLKEYLOGFILE works
- Generating a key log and pointing Wireshark at it
- Decrypting TLS captures
- Decrypting QUIC and HTTP/3
- Verifying decryption
- Exercises
Capturing Wi-Fi in Monitor Mode
- Adapters, drivers, and monitor mode
- Channel hopping
- 802.11 frame types
- Beacons, probes, and association
- Columns, filters, and expert info
- Practice: Reading a join
- Legal and privacy reality
- Exercises
Finding the Bottleneck: Expert Info, I/O Graphs, and TCP Stream Graphs
- The expert info window
- From symptom to hypothesis
- I/O graphs
- TCP stream graphs
- Network delay or application delay
- Complete case: ‘the app is slow’, start to finish
- Exercises
- Part V: Security Use Cases
Detecting Reconnaissance and Port Scans
- SYN scan anatomy
- Incomplete SYN handshake
- The conversations view
- Recognizing nmap probes
- False positives
- From scan to attribution
- Exercises
Malware Beacons and Call-Home Patterns
- What a Beacon Is
- Finding Beacon Candidates with tshark Summaries and Flow Statistics
- Measuring Beacon Interval and Interval Jitter
- DNS and HTTP Beacons versus HTTPS Beacons
- Beacon False Positives
- Practice: Hunting a Beacon in a Malware-Traffic-Analysis Capture
- Exercises
Suspicious DNS and Credential Leaks in Real Traces
- DNS as a channel: how tunneling works and what it looks like in queries
- Measuring query entropy and spotting long, suspicious labels in captures
- Finding plaintext credentials: follow-stream across HTTP, FTP, Telnet, and SMTP
- Exporting objects to pull exfiltrated files out of a pcap
- A forensics-style walkthrough: from odd DNS traffic to a remote shell
- Reporting what you found and what it means
- Exercises
- Part VI: Automation and Extension
Extracting Fields and Automating Analysis with tshark
- The one-liner
-T fields,-e, and-E: building exactly the rows you need- Summarizing traffic with shell pipelines
- Pulling fields from HTTP, DNS, and TLS conversations
- Looping over many files and scheduling jobs
- Why tshark fails in cron
- A canned daily traffic report you can ship today
- Exercises
Driving Captures and Analysis with Python: pyshark
- Installing pyshark
- Reading pcap and pcapng files
- Layers and fields
- Live capture
- Scheduling pyshark captures with cron
- Working example: flag suspicious DNS queries
- Exercises
Writing Lua Dissectors for Custom Protocols
- When you need a dissector
- Dissector anatomy
- Parsing the header
- Subtrees, columns, and expert annotations
- Port-based registration versus heuristic dissection
- Testing against a real capture
- Exercises
Appendix A: Display Filter and Capture Filter Quick Reference
- The Two Filter Families
- Display Filter Language
- Ready-Made Display Filters
- Capture Filters (BPF)
- Converting Between Families
Appendix B: Command-Line Toolkit Reference
- The Tools and Their Jobs
- Common Behaviors
- tshark: Capture and Read
- dumpcap
- capinfos
- editcap
- mergecap
- Companion Tools
- File Locations and Automation Notes
Appendix C: Where to Find Practice Captures
- Generate Your Own Traffic
- Official Wireshark Sample Captures
- Training Collections with Answer Keys
- Malware and Intrusion Traffic
- CTF and Competition Captures
- Broad and Benchmark Captures
- Finding Captures by Search
- Verify Before You Analyze
Appendix D: Lab Captures and Answers to the Exercises
- Chapter 1: Your First Capture: Installing Wireshark and Building Your Workspace
- Chapter 2: Where to Put the Sniffer: Hubs, SPAN, TAPs, Virtual Switches, and Remote Capture
- Chapter 3: Capturing the Right Traffic and Saving It Well: Capture Filters, pcapng, dumpcap, and Ring Buffers
- Chapter 4: Managing Capture Files at Scale: capinfos, editcap, and mergecap
- Chapter 5: The Display Filter Language: Syntax, Operators, and the Field Reference
- Chapter 6: Making Traffic Stand Out: Coloring Rules, Following Streams, and Time References
- Chapter 7: tshark: The Terminal Wireshark
- Chapter 8: Getting Online: ARP, DHCP, and DNS
- Chapter 9: TCP Under the Microscope: Handshakes, Retransmissions, and Sequence Analysis
- Chapter 10: Modern Web Protocols: HTTP/2 and HTTP/3
- Chapter 11: Voice and Video: SIP, RTP, and VoIP Analysis
- Chapter 12: Decrypting TLS and QUIC with Session Keys
- Chapter 13: Capturing Wi-Fi in Monitor Mode
- Chapter 14: Finding the Bottleneck: Expert Info, I/O Graphs, and TCP Stream Graphs
- Chapter 15: Detecting Reconnaissance and Port Scans
- Chapter 16: Malware Beacons and Call-Home Patterns
- Chapter 17: Suspicious DNS and Credential Leaks in Real Traces
- Chapter 18: Extracting Fields and Automating Analysis with tshark
- Chapter 19: Driving Captures and Analysis with Python: pyshark
- Chapter 20: Writing Lua Dissectors for Custom Protocols