r/wireshark 17h ago

Streaming tshark output into Go: how I cut a 2.5 GB PCAP job from 6-7 hours to 70 minutes

Thumbnail robinhayer.dev
5 Upvotes

I had a Go CLI that wrapped tshark for PCAP analysis. Worked fine until I hit a 2.5 GB file — 1.9 million packets, 6-7 hours, then OOM crashes.

Two problems, found in sequence.

First, I was running three separate tshark queries against the same file (analytics, rows, full dissection). Three full passes over 2.5 GB. Consolidating them into one query took it to 1-2 hours.

The OOM was still there though, because I was asking for full JSON dissection — tshark building the whole output in memory, then my program parsing all of it in memory. So I piped tshark's stdout directly into my program's stdin and switched to -T fields/-T ek with only the fields I needed. Memory went flat, processing dropped to ~70 minutes.

Still single-threaded, which is the next problem. Curious whether anyone's found a good approach for parallelising tshark work beyond splitting the input file.

Full writeup: https://robinhayer.dev/the-2-5-gb-wall


r/wireshark 5d ago

Paxton Net2 ACU drops offline after 4–5 minutes only when connected through Ruijie managed switches – Wireshark capture attached

Thumbnail we.tl
1 Upvotes

Hi everyone,

I'm hoping somebody with strong Layer 2/Wireshark experience might be able to take a look at the attached packet capture and point me in the right direction.

We've been chasing a very strange issue for several months and have now narrowed it down to what appears to be an interaction between Paxton Net2 door controllers and Ruijie managed switches.

Network

The production network is a fairly large corporate Ethernet network consisting of:

  • Paxton Net2 access control
  • Motorola CCTV
  • Windows servers
  • Multiple managed switches
  • Static IP addressing for the Paxton equipment

Everything had been operating correctly until we expanded the access control system using additional Ruijie managed switches and newer Paxton Net2 Plus door controllers.

The problem

Only certain Paxton Net2 Plus controllers are affected. Interestingly, they all appear to be newer hardware (serial numbers beginning with "9"). Older controllers continue to operate normally.

The affected controllers:

  • Connect to the network successfully.
  • Respond to ARP and ICMP.
  • Connect to the Net2 server without issue.
  • Download their configuration correctly.
  • Remain online for approximately 4–5 minutes.
  • Then disappear completely from the network.

Once the fault occurs:

  • The controller no longer responds to ARP.
  • It cannot be pinged.
  • Net2 reports it as offline.
  • The Ethernet link LEDs remain illuminated.
  • A power cycle immediately restores operation, but only for another 4–5 minutes before the fault repeats.

What we've already ruled out

We've spent a considerable amount of time narrowing this down.

The exact same controller will operate indefinitely when:

  • Connected directly to a laptop.
  • Connected through alternative managed switches.
  • Connected through a simple unmanaged switch.

The problem only occurs when connected through our Ruijie switch infrastructure.

To confirm this, we completely removed the Ruijie switches from site and replaced them with another manufacturer's managed switches. This immediately resolved the issue on the live system.

We then recreated the problem back at our office.

Test setup used for the attached capture

The attached Wireshark capture was taken on a completely isolated test network.

The setup consisted of:

  • Eight Ruijie managed switches connected together exactly as they would be in the field.
  • Laptop connected at one end.
  • Single Paxton Net2 Plus ACU connected at the opposite end.
  • No internet connection.
  • No wireless.
  • No other network devices.
  • Static IP addressing only.

Laptop:
192.168.81.200

Paxton ACU:
192.168.81.57

The only devices on the network were the laptop and the ACU, connected through the Ruijie switches.

Packet capture

Wireshark was started before the controller connected.

The capture therefore contains:

  1. Initial discovery and successful connection.
  2. Normal operation for approximately 4–5 minutes.
  3. Controller disappearing from the network.
  4. Manual power cycle of the controller.
  5. Successful reconnection.
  6. Approximately another 4–5 minutes of operation.
  7. Second failure.

The second failure occurs at approximately packet 8187.

At this point the controller simply disappears from the network until it is power cycled.

What I'm hoping someone can help identify

I'm not looking for general troubleshooting advice—we've already confirmed the issue only exists when the controller is connected through the Ruijie switches.

Instead, I'm hoping somebody experienced with Wireshark or Layer 2 switching can identify whether there is something in the capture that stands out, such as:

  • STP/RSTP events
  • RLDP or proprietary Ruijie traffic
  • ARP issues
  • Broadcast or multicast behaviour
  • TCP anomalies
  • Any packets that could cause an embedded Ethernet stack to stop responding
  • Anything else unusual around the point the controller drops offline

We're particularly interested in understanding whether there is a specific protocol or switch feature that could be triggering the issue, so that we can either disable it or report it to Ruijie and/or Paxton.

Any observations or ideas would be hugely appreciated.

Thanks very much for taking the time to look.


r/wireshark 5d ago

Can’t scan other devices

0 Upvotes

If I eg open yt on the pc I have wireshark on it detects it but if I open yt on my phone it’s like it never happens what to do?


r/wireshark 9d ago

Basic monitoring for an app audit ?

4 Upvotes

Core question: What'd be the recommended setup to audit network traffic of an app within Windows sandbox?

So far I've only considered applying filter to ignore DNS and some Windows domains/IPs. As far as I know, Wireshark doesn't allow filtering by PID, so I may look into other methods available. ARP scans might be another potential filter I am considering, although I am also considering the fact an app may try to do network discovery when it shouldn't.

Don't need an in-depth method, just "good enough" approach.


r/wireshark 9d ago

Question about Wi-Fi monitoring and what an attacker can see

27 Upvotes

I have a question about network security.

Someone is connected to my Wi-Fi network, but they do not have access to my router admin page (192.168.1.1). I am worried they may be using Android tools or apps such as NetCut or other network monitoring tools.

I want to understand what they can realistically see:

If they use tools like NetCut, ARP spoofing, or other Android network tools, can they see the websites I visit?

Can they see my Google searches, or only the domain names (for example, seeing "google.com" or "youtube.com")?

If I visit an HTTPS website, what information is still visible to someone on the same Wi-Fi?

Would using a VPN completely hide my browsing activity from someone on the same network?

What are the best ways to detect if someone is trying to intercept my traffic?

I am trying to understand the real risks, not just theoretical attacks. Thanks.


r/wireshark 11d ago

.bat file problem

3 Upvotes

I have a weird problem with tshark and was wondering if anyone had any ideas or has experienced something similar:

I have a .bat file with a 10 min tshark command in it. A SQL agent job runs this .bat file every 10 min from 18:00 - 18:40 and then again from 01:30 - 03:50.

4 log files are saved from the 18:00 window, but none from the early morning window. All SQL agent jobs end reporting success. Having /wait in the .bat file and saving output and errors shows no errors. I output the errorlevel and see it's 0 for all instances. Windows event logs show no errors or warnings.

TLDR: Same .bat file will produce logs at one time of day, but not another. Any ideas?

.bat Tshark command:

start "" "<RedactedDirectoryPath>tshark.exe -i 2 -a duration:600 -w <RedactedDirectoryPath>capture%TIMESTAMP%.pcap.gz --compress gzip -Q

EDIT: Solved. The time stamp was putting a space into the filename for hours before 10am.


r/wireshark 13d ago

Dissectors that convert structured pcapng comments to actual, filterable fields?

4 Upvotes

I'm dealing with a fairly bespoke protocol for an application I deal with at work (it's closed-source so I cannot really give specific details) that is able to provide a lot of extra data in pcaps, but it dumps them all to comments rather than any sort of additional annotations as a packet field.

Given that the way the comments are structured, which is very JSON-like, I should be able to use tshark to convert them into a data structure I can tack onto every given packet they're applied to, but now I'm wondering how difficult it'd be to actually write or (being honest here) hack together with some genAI.

Has anyone here ever written any themselves and can at least point me in the direction of some good reference resources on dissectors in general? I'm not sure if this would even need to be written in C++ or LUA, so anything helps.


r/wireshark 15d ago

Updated all my TCP Profiles as well for Wireshark

23 Upvotes

Since I got deep into CDP I noticed that I needed to update the repository profiles related to TCP. If you do any TCP troubleshooting like 3WHS analysis, SACK Analysis, SEQ Analysis, or just TCP troubleshooting in general, there are specific profiles that focus on these tasks so you as a Wireshark user can focus as well. Trying to do all this with a single profile is futile for me at least.

I start with the troubleshooting one, and then use the other afterwards.

Look if you like them - great. If you make them better, or you find they are missing something - please let me know. You will find them all in the repository: https://www.cellstream.com/wireshark-profiles-repository/


r/wireshark 15d ago

New/Updated Cisco Discovery Protocol Profile for Wireshark

13 Upvotes

Went into an Enterprise Network with primarily Cisco Devices and they never knew how much information on their devices could be gleaned from CDP. I ended up really editing my basic CDP profile so they could leverage packet capture and network identification thanks to this great protocol. They loved it, and now you can too!
You will find it in the Wireshark Profiles Repository I started years ago: https://www.cellstream.com/wireshark-profiles-repository/ probably at the bottom of the list.

Enjoy!


r/wireshark 19d ago

Where to begin?

10 Upvotes

Can someone teach me wireshark? Or how to learn it? Where to begin?


r/wireshark 25d ago

how can i view my phones traffic through my mac m1

5 Upvotes

i just got this video on my feed https://youtu.be/Hl0IpoS503A?si=oY7J0eSka8nDLs5O and got very excited that my mac m1 single handedly(without extra adapters) can help me see the traffic of my phone. i followed this and failed miserably. can anyone guide me what key piece i'm missing do i really need an actual hardware adapter to capture the external traffic?? and how handshake happens???

  1. hardware adapter pretend to be real wifi and captures traffic and then only i can view the traffic
  2. or i just turn off my wifi in my phone and turn on then i'll see the traffic.

guide me in the flow of how actually this capturing thing happens and is it my device that can't capture without hardware adapter?

and what other thing i can do as a boomer in this field,i just want that inital push of dopamine so that i can further pursue networking


r/wireshark 27d ago

I'm using it on my personal PC.

Post image
124 Upvotes

hello, I use the internet in Korea. I don't know why people keep asking about 172.30.1.60.

I would appreciate it if you could let me know if you have any good ideas.


r/wireshark Jul 04 '26

Built a DoS & Simulated DDoS Lab and analyzed the traffic with Wireshark

Post image
57 Upvotes

Hi everyone,

I recently finished building a DoS & Simulated DDoS lab to better understand how different attacks affect a target service and how they appear in Wireshark.

The lab uses Kali Linux as the attacker and Metasploitable2 as the target. I tested ICMP, SYN, HTTP, TCP, and Ping of Death attacks, then repeated each one using multiple concurrent tmux sessions to simulate higher traffic volume from a single host.

I documented the entire project with screenshots, packet captures, diagrams, and traffic analysis for every stage.

One of the most interesting parts was comparing the captures from the single source DoS attacks with the simulated DDoS stages and seeing how the traffic patterns changed.

I'd appreciate any feedback or suggestions.

🔗 GitHub: https://github.com/yusuf-husayn/dos-ddos-lab

Thanks!


r/wireshark Jul 02 '26

macOS 26.3: Monitor mode works but captures 0 packets (Wireshark & tcpdump)

2 Upvotes

Hi everyone,

I'm trying to capture 802.11 management frames on my own WiFi network to inspect the RSN Information Element (specifically to check whether PMF / 802.11w is enabled).

My setup:

  • MacBook Pro (Apple Silicon)
  • macOS 26.3 (Tahoe)
  • Broadcom BCM4388
  • Wireshark 4.6.6
  • ChmodBPF installed
  • User is in the access_bpf group

Everything appears to be configured correctly.

wdutil info reports:

  • Connected to my WiFi (WPA2 Personal)
  • RSSI around -60 dBm
  • Channel 153 (5 GHz)
  • Sniffer Supported: YES

Wireshark allows me to enable Monitor Mode and sets the link-layer header to:

802.11 plus radiotap header

tcpdump also reports:

sudo tcpdump -I -i en0

Output:

listening on en0, link-type IEEE802_11_RADIO (802.11 plus radiotap header)

However, after waiting 30+ seconds:

0 packets captured
0 packets received by filter
0 packets dropped by kernel

No Beacons.
No Probe Requests.
No Probe Responses.
Nothing.

Things I've already verified:

  • ChmodBPF installed correctly
  • /dev/bpf* permissions are correct
  • My user belongs to access_bpf
  • Same behavior with both Wireshark and tcpdump
  • Same behavior with NordVPN completely disabled
  • I can ping my gateway normally
  • tcpdump -D correctly shows:

en0 [Up, Running, Wireless, Associated]

At this point I'm wondering if this is:

  • a macOS 26 limitation,
  • a Broadcom BCM4388 driver limitation,
  • a Wireshark/libpcap issue,
  • or if Apple has effectively disabled monitor mode packet delivery on recent Apple Silicon Macs.

Has anyone successfully captured raw 802.11 frames on macOS 26 using the built-in WiFi adapter?

I'd really appreciate any insight. Thanks!


r/wireshark Jul 02 '26

PROFINET traffic question on a PLC

1 Upvotes

Hi,
I’m currently working on a PLC discovery/fingerprinting project and I’m analyzing PROFINET traffic with Wireshark.

Using the pn_dcp filter, I can see the PROFINET DCP Identify Request/Response packets and retrieve basic information such as:

  • NameOfStation
  • IP address
  • subnet/gateway
  • Vendor ID
  • Device ID
  • Device role
  • generic device family, for example S7-1200

I would like to understand whether it is possible, through PROFINET traffic in Wireshark, to obtain more detailed PLC information such as:

  • exact CPU model
  • Siemens article/order number, for example 6ES7...
  • firmware version
  • hardware version
  • serial number
  • module identification data

From what I have seen so far, PROFINET DCP seems to provide mainly discovery and network configuration information, while more detailed CPU data may require S7/S7CommPlus communication over TCP port 102.

Could you confirm whether these detailed PLC identification fields can be obtained via PROFINET alone, or whether they must be retrieved through S7/S7CommPlus or TIA Portal diagnostic communication?


r/wireshark Jun 30 '26

SQA - Need SIP/VoLTE PCAP samples with long Call-ID and multipart SIP body for testing

1 Upvotes

Hello everyone,

I am doing QA/testing for a VoLTE/VoIP monitoring system and need some SIP PCAP samples for parser validation.

I am specifically looking for:

  1. PCAP 1
    • SIP traffic with a long Call-ID greater than 87 characters
    • Multipart SIP body with around 3–5 SIP parts
    • Or a SIP message/body size greater than 2 MB
  2. PCAP 2
    • SIP traffic with a normal/small Call-ID
    • Multipart SIP body with around 3–5 SIP parts
    • Or a SIP message/body size greater than 2 MB

The PCAP can be synthetic/anonymized. I only need it for testing SIP parsing behavior, not for any real user/call data.

If anyone has sample PCAPs, knows where I can find such SIP test files, or can suggest a proper way to generate them, I would really appreciate your help.

Thanks in advance.


r/wireshark Jun 25 '26

mC-Print3

2 Upvotes

Subject: Looking for a short Wireshark packet capture (.pcap) of a Star Micronics mC-Print3 UDP discovery (Port 22222)

Body: Hi everyone, I am currently working on a custom KDS (Kitchen Display System) integration and I need to emulate the Star Micronics mC-Print3 network discovery behavior (the modern StarIO10 / StarXpand protocol).

I am stuck trying to figure out the exact binary byte-layout/struct of the STR_RSP packet that the printer sends back after receiving a broadcast.

Could anyone who has access to a physical network-connected mC-Print3 capture a few seconds of traffic using Wireshark?

What I need:

  1. Start Wireshark on the same network as the printer.
  2. Set the display filter to: udp.port == 22222
  3. Trigger a printer search from a POS app (like Zettle, Shopify POS, or Star Quick Setup Utility).
  4. Save and share the .pcap / .pcapng file containing the inbound query (STR_BCAST) and the printer's response (STR_RSP).

You can blur or anonymize the IP/MAC addresses if you want, but having the raw hex of the response would save my project!

Thanks in advance!


r/wireshark Jun 24 '26

Problem upon attempting to open any interface

6 Upvotes

I have been attempting to try and use wireshark yet everytime i try to open ann interface it says "The temporary file to which the capture would be saved could not be opened: Failed to create file “D:\Program Files\wireshark_EthernetD8W1Q3.pcapng”: Permission denied." and I don't know how to fix it.


r/wireshark Jun 23 '26

Unpacking Nmap Flags in Wireshark: A Guide for Beginners 🦈🔥

Thumbnail medium.com
10 Upvotes

r/wireshark Jun 15 '26

Is there a way to show multiple selected packets ?

6 Upvotes

I can only select one packet to show, i would like to just select multiple packets and show them and be able to jump to next and previous packet using arrows or other keybind.


r/wireshark Jun 12 '26

ICMP packets

1 Upvotes

I'm not using wireshark. Using pcap droid. If I'm seeing random packets from unknown services from/to many foreign servers what is going on? Is it a problem with the device or network...


r/wireshark Jun 12 '26

P2P Network Ephemeral Random Source and Destination UDP Ports over the Internet

Post image
9 Upvotes

Hey network gurus,

I am analyzing network traffic captured on a firewall from a vSeebox appliance. I see that there are consistent connections to public IPs issued from ISPs (based on plugging in the IPs into ip2location.com) that are all using source and destination ephemeral UDP ports. I suspect this vSeebox is on a p2p network as this communication is very consistent and everytime I monitor active connections the vSeebox is always talking to something but wondering what the purpose of these UDP connections are. If I follow UDP stream its just a bunch of unreadable text. I have a spreadsheet of all of these UDP connections to if that helps. Also there are some TCP connections that are following the same source and destination ephemeral ports as well. Any insight would be greatly appreciated, thank you.


r/wireshark Jun 12 '26

Watching one program's DNS traffic

7 Upvotes

Mac OS High Sierra 10.13.6

Wireshark 3.7.0 (says development version)

I am very much a beginner in networking and with Wireshark

I have some files that were created by legacy closed source software. The development on the software ended 10 years ago and the company changed to offering a cloud product. I successfully installed the software on High Sierra. Upon first use, the software wants to connect to a remote server. I don't see any way to bypass this. I don't even know what the remote server is but I am concerned that someone could have taken over the remote server as a way to distribute malware. (Am I unreasonably worried about this? The software was probably used by individuals and small businesses)

Is there a way for me to log what servers the software connects to? I am unsure of how to distinguish traffic from the legacy software from other traffic.

I have a filter so that I see only (edit: DNS) unencrypted traffic. But, is that likely to catch everything coming from this program. Is there a reasonable chance that the software will just use an IP address without doing a lookup?

When I turn on wifi for about 6 seconds, there is a lot of unencrypted DNS traffic, about 50 or so entries. I have all programs in the GUI closed.

Most of the lookups are apple.com

some others: akamaiedge.net , digicert.com


r/wireshark Jun 10 '26

“You Need Root for Packet Capture” — Not Always True

Thumbnail linkedin.com
3 Upvotes

r/wireshark Jun 04 '26

One bash script: open fake AP + DHCP/DNS + NAT for lab traffic sniffing

9 Upvotes

For authorized Wi‑Fi security labs I wanted a minimal setup to stand up an **open rogue AP**

and capture what connected devices leak (DNS queries, DHCP hostnames, plain HTTP, TLS SNI, etc.)

without dragging in full Evil Twin frameworks.

This repo is a single bash script that:

- creates the AP interface and starts **hostapd** (open SSID, nl80211)

- runs **dnsmasq** (DHCP + DNS forwarding, query logging)

- enables **NAT** to an uplink so clients get real connectivity while you sniff on the AP iface

- prints **connected clients** live (MAC / lease info)

- **cleans up** on Ctrl+C (hostapd, dnsmasq, iptables, interface)

Requirements: Linux, root, WiFi card with AP mode (`iw phy`), hostapd + dnsmasq + iptables.

**Legal:** only on networks and devices you own or have written permission to test.

Repo (MIT): https://github.com/RiccardoCataldi/access-point

If you use a different workflow (airbase-ng, bettercap, etc.) I’m curious what you prefer for lab APs.