tshark.md (11447B)
1 --- 2 title: "TShark" 3 description: "TShark CLI packet capture and analysis: filters, fields, follow streams and extraction for triage." 4 category: dfir 5 tags: [dfir, network-forensics, pcap] 6 tools: [TShark, Wireshark] 7 difficulty: intermediate 8 updated: "2026-08-09" 9 source: "vault:Tools/Tshark.md" 10 --- 11 12 # TShark 13 14 ## Overview 15 16 TShark is the command-line version of Wireshark, a powerful network protocol analyzer. It can capture packet data from a live network or read packets from a previously saved capture file. 17 18 --- 19 20 ## Basic Capture Commands 21 22 ### List Available Interfaces 23 24 ```bash 25 tshark -D 26 ``` 27 28 ### Capture Traffic from Specific Interface 29 30 ```bash 31 tshark -i eth0 32 tshark -i en0 # macOS 33 tshark -i 1 # Interface number from -D 34 ``` 35 36 ### Capture with Packet Count Limit 37 38 ```bash 39 tshark -i eth0 -c 100 # Capture 100 packets 40 ``` 41 42 ### Capture and Save to File 43 44 ```bash 45 tshark -i eth0 -w capture.pcap 46 tshark -i eth0 -w capture.pcap -c 1000 47 ``` 48 49 ### Capture with Time Limit 50 51 ```bash 52 tshark -i eth0 -a duration:60 -w capture.pcap # 60 seconds 53 ``` 54 55 ### Capture with File Size Limit 56 57 ```bash 58 tshark -i eth0 -a filesize:100000 -w capture.pcap # 100MB 59 ``` 60 61 --- 62 63 ## Reading and Analyzing Captured Data 64 65 ### Read from Capture File 66 67 ```bash 68 tshark -r capture.pcap 69 ``` 70 71 ### Read with Specific Protocol Display 72 73 ```bash 74 tshark -r capture.pcap -Y "http" 75 tshark -r capture.pcap -Y "dns" 76 ``` 77 78 ### Display Specific Fields 79 80 ```bash 81 tshark -r capture.pcap -T fields -e ip.src -e ip.dst -e tcp.port 82 ``` 83 84 ### Export to Different Formats 85 86 ```bash 87 tshark -r capture.pcap -T json > output.json 88 tshark -r capture.pcap -T ek > output.ek # Elastic-compatible JSON 89 tshark -r capture.pcap -T pdml > output.xml 90 tshark -r capture.pcap -T psml > output.xml 91 tshark -r capture.pcap -T text > output.txt 92 ``` 93 94 --- 95 96 ## Capturing Clear-Text Passwords and Credentials 97 98 ### HTTP Authentication (Basic Auth) 99 100 ```bash 101 # Capture HTTP Basic Authentication 102 tshark -i eth0 -Y "http.authorization" 103 tshark -r capture.pcap -Y "http.authorization" -T fields -e http.authorization 104 105 # Filter HTTP POST requests (often contain credentials) 106 tshark -r capture.pcap -Y "http.request.method == POST" 107 tshark -r capture.pcap -Y "http.request.method == POST" -T fields -e http.host -e http.request.uri -e http.file_data 108 ``` 109 110 ### FTP Credentials 111 112 ```bash 113 # FTP USER and PASS commands 114 tshark -i eth0 -Y "ftp.request.command == USER || ftp.request.command == PASS" 115 tshark -r capture.pcap -Y "ftp" -T fields -e ftp.request.command -e ftp.request.arg 116 ``` 117 118 ### Telnet Credentials 119 120 ```bash 121 # Capture telnet traffic (all clear-text) 122 tshark -i eth0 -Y "telnet" 123 tshark -r capture.pcap -Y "telnet" -T fields -e telnet.data 124 ``` 125 126 ### POP3/IMAP Credentials 127 128 ```bash 129 # POP3 credentials 130 tshark -r capture.pcap -Y "pop.request.command == USER || pop.request.command == PASS" 131 tshark -r capture.pcap -Y "pop" -T fields -e pop.request.command -e pop.request.parameter 132 133 # IMAP credentials 134 tshark -r capture.pcap -Y "imap.request contains LOGIN" 135 ``` 136 137 ### SMTP Authentication 138 139 ```bash 140 tshark -r capture.pcap -Y "smtp.req.command == AUTH" 141 tshark -r capture.pcap -Y "smtp" -T fields -e smtp.req.command -e smtp.req.parameter 142 ``` 143 144 ### Extract HTTP Form Data 145 146 ```bash 147 # Extract POST data containing passwords 148 tshark -r capture.pcap -Y "http.request.method == POST && urlencoded-form" -T fields -e http.file_data 149 150 # Look for specific keywords 151 tshark -r capture.pcap -Y 'http.file_data contains "password"' 152 ``` 153 154 ### Follow TCP Stream for Credentials 155 156 ```bash 157 # Follow specific TCP stream 158 tshark -r capture.pcap -z follow,tcp,ascii,0 # Stream 0 159 tshark -r capture.pcap -q -z follow,tcp,ascii,0 | grep -i "password\|user" 160 ``` 161 162 --- 163 164 ## Essential Display Filters 165 166 ### By Protocol 167 168 ```bash 169 tshark -r capture.pcap -Y "http" 170 tshark -r capture.pcap -Y "dns" 171 tshark -r capture.pcap -Y "tcp" 172 tshark -r capture.pcap -Y "udp" 173 tshark -r capture.pcap -Y "ssl" 174 tshark -r capture.pcap -Y "ssh" 175 ``` 176 177 ### By IP Address 178 179 ```bash 180 tshark -r capture.pcap -Y "ip.addr == 192.168.1.100" 181 tshark -r capture.pcap -Y "ip.src == 192.168.1.100" 182 tshark -r capture.pcap -Y "ip.dst == 192.168.1.100" 183 ``` 184 185 ### By Port 186 187 ```bash 188 tshark -r capture.pcap -Y "tcp.port == 80" 189 tshark -r capture.pcap -Y "tcp.dstport == 443" 190 tshark -r capture.pcap -Y "udp.port == 53" 191 ``` 192 193 ### By MAC Address 194 195 ```bash 196 tshark -r capture.pcap -Y "eth.addr == aa:bb:cc:dd:ee:ff" 197 ``` 198 199 ### Combining Filters 200 201 ```bash 202 tshark -r capture.pcap -Y "ip.src == 192.168.1.100 && tcp.port == 80" 203 tshark -r capture.pcap -Y "http && ip.addr == 192.168.1.100" 204 tshark -r capture.pcap -Y "tcp.port == 80 || tcp.port == 443" 205 ``` 206 207 ### Contains and Matches 208 209 ```bash 210 tshark -r capture.pcap -Y 'http.host contains "example.com"' 211 tshark -r capture.pcap -Y 'frame contains "password"' 212 tshark -r capture.pcap -Y 'http.request.uri matches "login"' 213 ``` 214 215 --- 216 217 ## Statistics and Analysis 218 219 ### Protocol Hierarchy Statistics 220 221 ```bash 222 tshark -r capture.pcap -q -z io,phs 223 ``` 224 225 ### Conversation Statistics 226 227 ```bash 228 tshark -r capture.pcap -q -z conv,tcp 229 tshark -r capture.pcap -q -z conv,udp 230 tshark -r capture.pcap -q -z conv,ip 231 ``` 232 233 ### HTTP Statistics 234 235 ```bash 236 tshark -r capture.pcap -q -z http,tree 237 tshark -r capture.pcap -q -z http_req,tree 238 tshark -r capture.pcap -q -z http_srv,tree 239 ``` 240 241 ### DNS Statistics 242 243 ```bash 244 tshark -r capture.pcap -q -z dns,tree 245 ``` 246 247 ### Endpoints 248 249 ```bash 250 tshark -r capture.pcap -q -z endpoints,tcp 251 tshark -r capture.pcap -q -z endpoints,ip 252 ``` 253 254 ### Export HTTP Objects 255 256 ```bash 257 tshark -r capture.pcap --export-objects http,/path/to/output/ 258 ``` 259 260 --- 261 262 ## Reference Table: Common Options and Filters 263 264 | Option | Description | Example | 265 |:---|:---|:---| 266 | `-D` | List available capture interfaces | `tshark -D` | 267 | `-i <interface>` | Specify capture interface | `tshark -i eth0` | 268 | `-r <file>` | Read from capture file | `tshark -r capture.pcap` | 269 | `-w <file>` | Write to capture file | `tshark -w output.pcap` | 270 | `-c <count>` | Capture n packets then stop | `tshark -c 1000` | 271 | `-a <criterion>` | Stop capture on condition | `tshark -a duration:60` | 272 | `-Y <filter>` | Display filter (Wireshark syntax) | `tshark -Y "http"` | 273 | `-f <filter>` | Capture filter (BPF syntax) | `tshark -f "port 80"` | 274 | `-T <format>` | Output format | `tshark -T json` | 275 | `-e <field>` | Display specific field | `tshark -e ip.src` | 276 | `-q` | Quiet mode (for statistics) | `tshark -q -z io,phs` | 277 | `-z <statistics>` | Print statistics | `tshark -z http,tree` | 278 | `-V` | Verbose packet details | `tshark -V` | 279 | `-x` | Print hex dump | `tshark -x` | 280 | `-n` | Disable name resolution | `tshark -n` | 281 | `-N <name>` | Enable name resolution | `tshark -N mntC` | 282 | `-E` | Field output options | `tshark -T fields -E separator=,` | 283 284 --- 285 286 ## Capture Filters (BPF Syntax) 287 288 | Filter | Description | Example | 289 |:---|:---|:---| 290 | `host <ip>` | Traffic to/from host | `tshark -f "host 192.168.1.100"` | 291 | `src host <ip>` | Traffic from host | `tshark -f "src host 192.168.1.100"` | 292 | `dst host <ip>` | Traffic to host | `tshark -f "dst host 192.168.1.100"` | 293 | `port <port>` | Traffic on port | `tshark -f "port 80"` | 294 | `src port <port>` | Source port | `tshark -f "src port 1234"` | 295 | `dst port <port>` | Destination port | `tshark -f "dst port 443"` | 296 | `tcp` | TCP traffic only | `tshark -f "tcp"` | 297 | `udp` | UDP traffic only | `tshark -f "udp"` | 298 | `net <network>` | Traffic to/from network | `tshark -f "net 192.168.1.0/24"` | 299 | `portrange <p1>-<p2>` | Port range | `tshark -f "portrange 1-1024"` | 300 301 --- 302 303 ## Display Filters for Common Protocols 304 305 | Protocol | Filter Examples | 306 |:---|:---| 307 | **HTTP** | `http` | 308 | | `http.request.method == "GET"` | 309 | | `http.response.code == 200` | 310 | | `http.host == "example.com"` | 311 | **HTTPS/TLS** | `ssl` or `tls` | 312 | | `ssl.handshake.type == 1` (Client Hello) | 313 | **DNS** | `dns` | 314 | | `dns.qry.name == "example.com"` | 315 | **FTP** | `ftp` | 316 | | `ftp.request.command == "USER"` | 317 | **SSH** | `ssh` | 318 | **Telnet** | `telnet` | 319 | **SMB** | `smb` or `smb2` | 320 | **SMTP** | `smtp` | 321 | **POP3** | `pop` | 322 | **IMAP** | `imap` | 323 | **ARP** | `arp` | 324 | **ICMP** | `icmp` | 325 326 --- 327 328 ## Advanced Examples 329 330 ### Capture Only Unencrypted HTTP Traffic 331 332 ```bash 333 tshark -i eth0 -f "tcp port 80" -Y "http" 334 ``` 335 336 ### Find All Passwords in Capture 337 338 ```bash 339 tshark -r capture.pcap -Y 'frame contains "password" || frame contains "passwd" || frame contains "pwd"' -T fields -e frame.number -e ip.src -e ip.dst -e text 340 ``` 341 342 ### Extract All URLs 343 344 ```bash 345 tshark -r capture.pcap -Y "http.request" -T fields -e http.host -e http.request.uri | sed 's/\t//' 346 ``` 347 348 ### Monitor Live Traffic with Filters 349 350 ```bash 351 tshark -i eth0 -Y "http.request || dns.qry.name" -T fields -e frame.time -e ip.src -e http.host -e dns.qry.name 352 ``` 353 354 ### Capture Credentials from Multiple Protocols 355 356 ```bash 357 tshark -i eth0 -Y "ftp || telnet || http.authorization || pop || imap" -w credentials.pcap 358 ``` 359 360 ### Ring Buffer Capture (Rotating Files) 361 362 ```bash 363 tshark -i eth0 -b filesize:50000 -b files:5 -w capture.pcap 364 # Creates capture_00001.pcap, capture_00002.pcap, etc. 365 ``` 366 367 ### Capture with Verbose Output 368 369 ```bash 370 tshark -i eth0 -V -c 10 371 ``` 372 373 ### Filter Non-Encrypted Web Traffic 374 375 ```bash 376 tshark -r capture.pcap -Y "http && !ssl" -T fields -e ip.src -e ip.dst -e http.host -e http.request.uri 377 ``` 378 379 --- 380 381 ## Credential Extraction Examples 382 383 ### Extract FTP Credentials 384 385 ```bash 386 tshark -r capture.pcap -Y "ftp.request.command == USER" -T fields -e ip.src -e ftp.request.arg > ftp_users.txt 387 tshark -r capture.pcap -Y "ftp.request.command == PASS" -T fields -e ip.src -e ftp.request.arg > ftp_passwords.txt 388 ``` 389 390 ### Extract HTTP Basic Auth 391 392 ```bash 393 tshark -r capture.pcap -Y "http.authorization" -T fields -e ip.src -e http.host -e http.authorization 394 ``` 395 396 ### Extract HTTP POST Data 397 398 ```bash 399 tshark -r capture.pcap -Y "http.request.method == POST" -T fields -e ip.src -e http.host -e http.file_data | grep -i "username\|password" 400 ``` 401 402 ### Monitor for Credentials in Real-Time 403 404 ```bash 405 tshark -i eth0 -Y "ftp || http.authorization || telnet || pop || smtp.req.command == AUTH" -T fields -e frame.time -e ip.src -e ip.dst -e tcp.port 406 ``` 407 408 --- 409 410 ## Tips and Best Practices 411 412 1. **Use Capture Filters** (`-f`) to reduce captured data size 413 2. **Use Display Filters** (`-Y`) for analysis after capture 414 3. **Root/Admin Required** for capturing on most interfaces 415 4. **Promiscuous Mode** is enabled by default (capture all traffic on network segment) 416 5. **Name Resolution** can slow down capture; use `-n` to disable 417 6. **Large Captures** should be split using `-b` option 418 7. **Combine with grep/awk** for advanced text processing 419 8. **Export Objects** to extract files from capture 420 421 --- 422 423 ## Security and Legal Considerations 424 425 > **Important —** Only capture traffic on networks you own or have explicit permission to monitor. Capturing credentials without authorization may be illegal. Use for legitimate security testing, education, and network troubleshooting only. Be aware of privacy laws and regulations in your jurisdiction. Encrypted traffic (HTTPS, SSH, etc.) will not reveal passwords without additional steps. 426 427 --- 428 429 ## Quick Start Example Workflow 430 431 ```bash 432 # 1. List interfaces 433 tshark -D 434 435 # 2. Capture 1000 packets from eth0 436 tshark -i eth0 -c 1000 -w capture.pcap 437 438 # 3. Analyze for HTTP traffic 439 tshark -r capture.pcap -Y "http" 440 441 # 4. Look for credentials 442 tshark -r capture.pcap -Y "ftp || http.authorization" 443 444 # 5. Extract specific fields 445 tshark -r capture.pcap -Y "http.request" -T fields -e ip.src -e http.host -e http.request.uri 446 ```