Choose a harmless exercise
Packet captures can reveal addresses, visited services and sometimes plaintext data. Use your own lab activity, avoid capturing customer traffic and keep the recording short. Wireshark on a switched network does not automatically see every other computer's packets.
Install and select the interface
- Download Wireshark from its official site or a trusted distribution repository.
- Install the supported packet-capture component required by your operating system. On Windows this commonly involves Npcap; review its applicable licence for your use.
- Identify the interface actually carrying your test traffic: Ethernet, Wi-Fi, VPN or loopback.
- Start a capture on that interface, perform one known action such as opening a public page, then stop after a short interval.
Do not capture indefinitely while you decide what to inspect. A narrow question helps reduce sensitive data and file size.
Read the three panes
The packet list is the timeline. Selecting a packet shows protocol fields in the packet-details pane. The bytes pane displays the underlying bytes associated with those fields. This lets you move from a high-level label to the exact recorded data.
Start with time, source, destination and protocol. Select one packet related to your test action. Expand Ethernet or the relevant link layer, IP and TCP or UDP sections. Not every capture uses Ethernet headers.
Verify that you captured the right traffic
Compare packet timing with your known action and check that your device's expected address appears. A VPN can change where traffic is visible; an encrypted tunnel on one interface and inner packets on another are different observations.
If no packets appear, confirm interface choice, capture permissions and the capture driver. An empty capture is not proof that the computer is making no connections.
Save responsibly
Save only a necessary capture in pcapng format and keep it private. Make a sanitised demonstration capture if you need teaching material. Do not post a real business capture merely because passwords appear encrypted; metadata and application data can still be sensitive.
Common misconceptions
HTTPS normally hides application contents without the appropriate authorised decryption setup. A visible TLS exchange is not proof of malicious encryption. Capturing packets does not fix a network issue by itself; it provides evidence for a focused diagnosis. Continue with display filters and conversation analysis once you have a short, understood sample.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.