February 2019
Beginner to intermediate
302 pages
7h 58m
English
TShark is another command-line network protocol analyzer. It has similar capabilities to Wireshark for capturing traffic on a live network and even reading offline captures that were previously saved for further analysis. Many of its features are like the previously mentioned tool, the tcpdump tool.
To capture packets and output the data into a file, we can use the tshark –i <interface> -w <output file> command:
![]()
Once again, notice the live traffic isn’t displayed on the Terminal as it is being written to the tsharkcapture.pcap file. However, without using the –w parameter, we’ll see all the traffic that is hitting our wlan0 interface: ...
Read now
Unlock full access