MYTHOSAI

Tool tutorials / PRACTICAL GUIDE

Your first Wireshark packet capture

Capture a short piece of your own traffic and learn the three main views.

Before you start

Free Wireshark, its supported capture driver and permission to inspect the selected traffic.

Choose a harmless exercise

Packet captures can reveal addresses, visited services and sometimes plaintext data. Use your own lab activity, avoid capturing customer traffic and keep the recording short. Wireshark on a switched network does not automatically see every other computer's packets.

Install and select the interface

  1. Download Wireshark from its official site or a trusted distribution repository.
  2. Install the supported packet-capture component required by your operating system. On Windows this commonly involves Npcap; review its applicable licence for your use.
  3. Identify the interface actually carrying your test traffic: Ethernet, Wi-Fi, VPN or loopback.
  4. Start a capture on that interface, perform one known action such as opening a public page, then stop after a short interval.

Do not capture indefinitely while you decide what to inspect. A narrow question helps reduce sensitive data and file size.

Read the three panes

The packet list is the timeline. Selecting a packet shows protocol fields in the packet-details pane. The bytes pane displays the underlying bytes associated with those fields. This lets you move from a high-level label to the exact recorded data.

Start with time, source, destination and protocol. Select one packet related to your test action. Expand Ethernet or the relevant link layer, IP and TCP or UDP sections. Not every capture uses Ethernet headers.

Verify that you captured the right traffic

Compare packet timing with your known action and check that your device's expected address appears. A VPN can change where traffic is visible; an encrypted tunnel on one interface and inner packets on another are different observations.

If no packets appear, confirm interface choice, capture permissions and the capture driver. An empty capture is not proof that the computer is making no connections.

Save responsibly

Save only a necessary capture in pcapng format and keep it private. Make a sanitised demonstration capture if you need teaching material. Do not post a real business capture merely because passwords appear encrypted; metadata and application data can still be sensitive.

Common misconceptions

HTTPS normally hides application contents without the appropriate authorised decryption setup. A visible TLS exchange is not proof of malicious encryption. Capturing packets does not fix a network issue by itself; it provides evidence for a focused diagnosis. Continue with display filters and conversation analysis once you have a short, understood sample.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.