In this short course, we covered the command line version of Wireshark, that is, Tshark. We discussed difference between Wireshark and Tshark, operations mode of Tshark such as live capture and PCAP analysis, Tshark filters, advanced filtering, conditional data extraction and extracting analytical insights by following streams, conversations and exporting objects.
In the practical scenario, we solved the following rooms from TryHackMe:
TShark: The Basics
TShark: CLI Wireshark Features
TShark Challenge I: Teamwork
TShark Challenge II: Directory
The course contains the below contents:
– Intro to Tshark & Wireshark vs Tshark
– Sniffing packets
– PCAP Analysis
– Display filters vs capture filters
– Extracting statistics, protocol breakdown, conversations and endpoints
– Following streams, exporting objects and credentials
- Advanced filtering, field extraction and conditional extraction