daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

tshark.md (11447B)


      1 ---
      2 title: "TShark"
      3 description: "TShark CLI packet capture and analysis: filters, fields, follow streams and extraction for triage."
      4 category: dfir
      5 tags: [dfir, network-forensics, pcap]
      6 tools: [TShark, Wireshark]
      7 difficulty: intermediate
      8 updated: "2026-08-09"
      9 source: "vault:Tools/Tshark.md"
     10 ---
     11 
     12 # TShark
     13 
     14 ## Overview
     15 
     16 TShark is the command-line version of Wireshark, a powerful network protocol analyzer. It can capture packet data from a live network or read packets from a previously saved capture file.
     17 
     18 ---
     19 
     20 ## Basic Capture Commands
     21 
     22 ### List Available Interfaces
     23 
     24 ```bash
     25 tshark -D
     26 ```
     27 
     28 ### Capture Traffic from Specific Interface
     29 
     30 ```bash
     31 tshark -i eth0
     32 tshark -i en0  # macOS
     33 tshark -i 1    # Interface number from -D
     34 ```
     35 
     36 ### Capture with Packet Count Limit
     37 
     38 ```bash
     39 tshark -i eth0 -c 100  # Capture 100 packets
     40 ```
     41 
     42 ### Capture and Save to File
     43 
     44 ```bash
     45 tshark -i eth0 -w capture.pcap
     46 tshark -i eth0 -w capture.pcap -c 1000
     47 ```
     48 
     49 ### Capture with Time Limit
     50 
     51 ```bash
     52 tshark -i eth0 -a duration:60 -w capture.pcap  # 60 seconds
     53 ```
     54 
     55 ### Capture with File Size Limit
     56 
     57 ```bash
     58 tshark -i eth0 -a filesize:100000 -w capture.pcap  # 100MB
     59 ```
     60 
     61 ---
     62 
     63 ## Reading and Analyzing Captured Data
     64 
     65 ### Read from Capture File
     66 
     67 ```bash
     68 tshark -r capture.pcap
     69 ```
     70 
     71 ### Read with Specific Protocol Display
     72 
     73 ```bash
     74 tshark -r capture.pcap -Y "http"
     75 tshark -r capture.pcap -Y "dns"
     76 ```
     77 
     78 ### Display Specific Fields
     79 
     80 ```bash
     81 tshark -r capture.pcap -T fields -e ip.src -e ip.dst -e tcp.port
     82 ```
     83 
     84 ### Export to Different Formats
     85 
     86 ```bash
     87 tshark -r capture.pcap -T json > output.json
     88 tshark -r capture.pcap -T ek > output.ek     # Elastic-compatible JSON
     89 tshark -r capture.pcap -T pdml > output.xml
     90 tshark -r capture.pcap -T psml > output.xml
     91 tshark -r capture.pcap -T text > output.txt
     92 ```
     93 
     94 ---
     95 
     96 ## Capturing Clear-Text Passwords and Credentials
     97 
     98 ### HTTP Authentication (Basic Auth)
     99 
    100 ```bash
    101 # Capture HTTP Basic Authentication
    102 tshark -i eth0 -Y "http.authorization"
    103 tshark -r capture.pcap -Y "http.authorization" -T fields -e http.authorization
    104 
    105 # Filter HTTP POST requests (often contain credentials)
    106 tshark -r capture.pcap -Y "http.request.method == POST"
    107 tshark -r capture.pcap -Y "http.request.method == POST" -T fields -e http.host -e http.request.uri -e http.file_data
    108 ```
    109 
    110 ### FTP Credentials
    111 
    112 ```bash
    113 # FTP USER and PASS commands
    114 tshark -i eth0 -Y "ftp.request.command == USER || ftp.request.command == PASS"
    115 tshark -r capture.pcap -Y "ftp" -T fields -e ftp.request.command -e ftp.request.arg
    116 ```
    117 
    118 ### Telnet Credentials
    119 
    120 ```bash
    121 # Capture telnet traffic (all clear-text)
    122 tshark -i eth0 -Y "telnet"
    123 tshark -r capture.pcap -Y "telnet" -T fields -e telnet.data
    124 ```
    125 
    126 ### POP3/IMAP Credentials
    127 
    128 ```bash
    129 # POP3 credentials
    130 tshark -r capture.pcap -Y "pop.request.command == USER || pop.request.command == PASS"
    131 tshark -r capture.pcap -Y "pop" -T fields -e pop.request.command -e pop.request.parameter
    132 
    133 # IMAP credentials
    134 tshark -r capture.pcap -Y "imap.request contains LOGIN"
    135 ```
    136 
    137 ### SMTP Authentication
    138 
    139 ```bash
    140 tshark -r capture.pcap -Y "smtp.req.command == AUTH"
    141 tshark -r capture.pcap -Y "smtp" -T fields -e smtp.req.command -e smtp.req.parameter
    142 ```
    143 
    144 ### Extract HTTP Form Data
    145 
    146 ```bash
    147 # Extract POST data containing passwords
    148 tshark -r capture.pcap -Y "http.request.method == POST && urlencoded-form" -T fields -e http.file_data
    149 
    150 # Look for specific keywords
    151 tshark -r capture.pcap -Y 'http.file_data contains "password"'
    152 ```
    153 
    154 ### Follow TCP Stream for Credentials
    155 
    156 ```bash
    157 # Follow specific TCP stream
    158 tshark -r capture.pcap -z follow,tcp,ascii,0  # Stream 0
    159 tshark -r capture.pcap -q -z follow,tcp,ascii,0 | grep -i "password\|user"
    160 ```
    161 
    162 ---
    163 
    164 ## Essential Display Filters
    165 
    166 ### By Protocol
    167 
    168 ```bash
    169 tshark -r capture.pcap -Y "http"
    170 tshark -r capture.pcap -Y "dns"
    171 tshark -r capture.pcap -Y "tcp"
    172 tshark -r capture.pcap -Y "udp"
    173 tshark -r capture.pcap -Y "ssl"
    174 tshark -r capture.pcap -Y "ssh"
    175 ```
    176 
    177 ### By IP Address
    178 
    179 ```bash
    180 tshark -r capture.pcap -Y "ip.addr == 192.168.1.100"
    181 tshark -r capture.pcap -Y "ip.src == 192.168.1.100"
    182 tshark -r capture.pcap -Y "ip.dst == 192.168.1.100"
    183 ```
    184 
    185 ### By Port
    186 
    187 ```bash
    188 tshark -r capture.pcap -Y "tcp.port == 80"
    189 tshark -r capture.pcap -Y "tcp.dstport == 443"
    190 tshark -r capture.pcap -Y "udp.port == 53"
    191 ```
    192 
    193 ### By MAC Address
    194 
    195 ```bash
    196 tshark -r capture.pcap -Y "eth.addr == aa:bb:cc:dd:ee:ff"
    197 ```
    198 
    199 ### Combining Filters
    200 
    201 ```bash
    202 tshark -r capture.pcap -Y "ip.src == 192.168.1.100 && tcp.port == 80"
    203 tshark -r capture.pcap -Y "http && ip.addr == 192.168.1.100"
    204 tshark -r capture.pcap -Y "tcp.port == 80 || tcp.port == 443"
    205 ```
    206 
    207 ### Contains and Matches
    208 
    209 ```bash
    210 tshark -r capture.pcap -Y 'http.host contains "example.com"'
    211 tshark -r capture.pcap -Y 'frame contains "password"'
    212 tshark -r capture.pcap -Y 'http.request.uri matches "login"'
    213 ```
    214 
    215 ---
    216 
    217 ## Statistics and Analysis
    218 
    219 ### Protocol Hierarchy Statistics
    220 
    221 ```bash
    222 tshark -r capture.pcap -q -z io,phs
    223 ```
    224 
    225 ### Conversation Statistics
    226 
    227 ```bash
    228 tshark -r capture.pcap -q -z conv,tcp
    229 tshark -r capture.pcap -q -z conv,udp
    230 tshark -r capture.pcap -q -z conv,ip
    231 ```
    232 
    233 ### HTTP Statistics
    234 
    235 ```bash
    236 tshark -r capture.pcap -q -z http,tree
    237 tshark -r capture.pcap -q -z http_req,tree
    238 tshark -r capture.pcap -q -z http_srv,tree
    239 ```
    240 
    241 ### DNS Statistics
    242 
    243 ```bash
    244 tshark -r capture.pcap -q -z dns,tree
    245 ```
    246 
    247 ### Endpoints
    248 
    249 ```bash
    250 tshark -r capture.pcap -q -z endpoints,tcp
    251 tshark -r capture.pcap -q -z endpoints,ip
    252 ```
    253 
    254 ### Export HTTP Objects
    255 
    256 ```bash
    257 tshark -r capture.pcap --export-objects http,/path/to/output/
    258 ```
    259 
    260 ---
    261 
    262 ## Reference Table: Common Options and Filters
    263 
    264 | Option | Description | Example |
    265 |:---|:---|:---|
    266 | `-D` | List available capture interfaces | `tshark -D` |
    267 | `-i <interface>` | Specify capture interface | `tshark -i eth0` |
    268 | `-r <file>` | Read from capture file | `tshark -r capture.pcap` |
    269 | `-w <file>` | Write to capture file | `tshark -w output.pcap` |
    270 | `-c <count>` | Capture n packets then stop | `tshark -c 1000` |
    271 | `-a <criterion>` | Stop capture on condition | `tshark -a duration:60` |
    272 | `-Y <filter>` | Display filter (Wireshark syntax) | `tshark -Y "http"` |
    273 | `-f <filter>` | Capture filter (BPF syntax) | `tshark -f "port 80"` |
    274 | `-T <format>` | Output format | `tshark -T json` |
    275 | `-e <field>` | Display specific field | `tshark -e ip.src` |
    276 | `-q` | Quiet mode (for statistics) | `tshark -q -z io,phs` |
    277 | `-z <statistics>` | Print statistics | `tshark -z http,tree` |
    278 | `-V` | Verbose packet details | `tshark -V` |
    279 | `-x` | Print hex dump | `tshark -x` |
    280 | `-n` | Disable name resolution | `tshark -n` |
    281 | `-N <name>` | Enable name resolution | `tshark -N mntC` |
    282 | `-E` | Field output options | `tshark -T fields -E separator=,` |
    283 
    284 ---
    285 
    286 ## Capture Filters (BPF Syntax)
    287 
    288 | Filter | Description | Example |
    289 |:---|:---|:---|
    290 | `host <ip>` | Traffic to/from host | `tshark -f "host 192.168.1.100"` |
    291 | `src host <ip>` | Traffic from host | `tshark -f "src host 192.168.1.100"` |
    292 | `dst host <ip>` | Traffic to host | `tshark -f "dst host 192.168.1.100"` |
    293 | `port <port>` | Traffic on port | `tshark -f "port 80"` |
    294 | `src port <port>` | Source port | `tshark -f "src port 1234"` |
    295 | `dst port <port>` | Destination port | `tshark -f "dst port 443"` |
    296 | `tcp` | TCP traffic only | `tshark -f "tcp"` |
    297 | `udp` | UDP traffic only | `tshark -f "udp"` |
    298 | `net <network>` | Traffic to/from network | `tshark -f "net 192.168.1.0/24"` |
    299 | `portrange <p1>-<p2>` | Port range | `tshark -f "portrange 1-1024"` |
    300 
    301 ---
    302 
    303 ## Display Filters for Common Protocols
    304 
    305 | Protocol | Filter Examples |
    306 |:---|:---|
    307 | **HTTP** | `http` |
    308 |  | `http.request.method == "GET"` |
    309 |  | `http.response.code == 200` |
    310 |  | `http.host == "example.com"` |
    311 | **HTTPS/TLS** | `ssl` or `tls` |
    312 |  | `ssl.handshake.type == 1` (Client Hello) |
    313 | **DNS** | `dns` |
    314 |  | `dns.qry.name == "example.com"` |
    315 | **FTP** | `ftp` |
    316 |  | `ftp.request.command == "USER"` |
    317 | **SSH** | `ssh` |
    318 | **Telnet** | `telnet` |
    319 | **SMB** | `smb` or `smb2` |
    320 | **SMTP** | `smtp` |
    321 | **POP3** | `pop` |
    322 | **IMAP** | `imap` |
    323 | **ARP** | `arp` |
    324 | **ICMP** | `icmp` |
    325 
    326 ---
    327 
    328 ## Advanced Examples
    329 
    330 ### Capture Only Unencrypted HTTP Traffic
    331 
    332 ```bash
    333 tshark -i eth0 -f "tcp port 80" -Y "http"
    334 ```
    335 
    336 ### Find All Passwords in Capture
    337 
    338 ```bash
    339 tshark -r capture.pcap -Y 'frame contains "password" || frame contains "passwd" || frame contains "pwd"' -T fields -e frame.number -e ip.src -e ip.dst -e text
    340 ```
    341 
    342 ### Extract All URLs
    343 
    344 ```bash
    345 tshark -r capture.pcap -Y "http.request" -T fields -e http.host -e http.request.uri | sed 's/\t//'
    346 ```
    347 
    348 ### Monitor Live Traffic with Filters
    349 
    350 ```bash
    351 tshark -i eth0 -Y "http.request || dns.qry.name" -T fields -e frame.time -e ip.src -e http.host -e dns.qry.name
    352 ```
    353 
    354 ### Capture Credentials from Multiple Protocols
    355 
    356 ```bash
    357 tshark -i eth0 -Y "ftp || telnet || http.authorization || pop || imap" -w credentials.pcap
    358 ```
    359 
    360 ### Ring Buffer Capture (Rotating Files)
    361 
    362 ```bash
    363 tshark -i eth0 -b filesize:50000 -b files:5 -w capture.pcap
    364 # Creates capture_00001.pcap, capture_00002.pcap, etc.
    365 ```
    366 
    367 ### Capture with Verbose Output
    368 
    369 ```bash
    370 tshark -i eth0 -V -c 10
    371 ```
    372 
    373 ### Filter Non-Encrypted Web Traffic
    374 
    375 ```bash
    376 tshark -r capture.pcap -Y "http && !ssl" -T fields -e ip.src -e ip.dst -e http.host -e http.request.uri
    377 ```
    378 
    379 ---
    380 
    381 ## Credential Extraction Examples
    382 
    383 ### Extract FTP Credentials
    384 
    385 ```bash
    386 tshark -r capture.pcap -Y "ftp.request.command == USER" -T fields -e ip.src -e ftp.request.arg > ftp_users.txt
    387 tshark -r capture.pcap -Y "ftp.request.command == PASS" -T fields -e ip.src -e ftp.request.arg > ftp_passwords.txt
    388 ```
    389 
    390 ### Extract HTTP Basic Auth
    391 
    392 ```bash
    393 tshark -r capture.pcap -Y "http.authorization" -T fields -e ip.src -e http.host -e http.authorization
    394 ```
    395 
    396 ### Extract HTTP POST Data
    397 
    398 ```bash
    399 tshark -r capture.pcap -Y "http.request.method == POST" -T fields -e ip.src -e http.host -e http.file_data | grep -i "username\|password"
    400 ```
    401 
    402 ### Monitor for Credentials in Real-Time
    403 
    404 ```bash
    405 tshark -i eth0 -Y "ftp || http.authorization || telnet || pop || smtp.req.command == AUTH" -T fields -e frame.time -e ip.src -e ip.dst -e tcp.port
    406 ```
    407 
    408 ---
    409 
    410 ## Tips and Best Practices
    411 
    412 1. **Use Capture Filters** (`-f`) to reduce captured data size
    413 2. **Use Display Filters** (`-Y`) for analysis after capture
    414 3. **Root/Admin Required** for capturing on most interfaces
    415 4. **Promiscuous Mode** is enabled by default (capture all traffic on network segment)
    416 5. **Name Resolution** can slow down capture; use `-n` to disable
    417 6. **Large Captures** should be split using `-b` option
    418 7. **Combine with grep/awk** for advanced text processing
    419 8. **Export Objects** to extract files from capture
    420 
    421 ---
    422 
    423 ## Security and Legal Considerations
    424 
    425 > **Important —** Only capture traffic on networks you own or have explicit permission to monitor. Capturing credentials without authorization may be illegal. Use for legitimate security testing, education, and network troubleshooting only. Be aware of privacy laws and regulations in your jurisdiction. Encrypted traffic (HTTPS, SSH, etc.) will not reveal passwords without additional steps.
    426 
    427 ---
    428 
    429 ## Quick Start Example Workflow
    430 
    431 ```bash
    432 # 1. List interfaces
    433 tshark -D
    434 
    435 # 2. Capture 1000 packets from eth0
    436 tshark -i eth0 -c 1000 -w capture.pcap
    437 
    438 # 3. Analyze for HTTP traffic
    439 tshark -r capture.pcap -Y "http"
    440 
    441 # 4. Look for credentials
    442 tshark -r capture.pcap -Y "ftp || http.authorization"
    443 
    444 # 5. Extract specific fields
    445 tshark -r capture.pcap -Y "http.request" -T fields -e ip.src -e http.host -e http.request.uri
    446 ```