Wireshark Tutorial for Beginners: Capture, Filter and Spot Suspicious Traffic
A practical walk-through of Wireshark: installing it, finding your way around, using filters, following streams, reading the TCP handshake, analysing DNS and HTTP, and recognising ten suspicious-traffic patterns. A filter cheat table is included.
Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations are original. Capture traffic only on networks you own or have written permission to monitor, and treat captures as sensitive because they can contain passwords and personal data. See the official Wireshark documentation for full details.
1. Installation
Windows
Download the installer from wireshark.org. It offers to install Npcap, the capture driver. Accept it.
macOS
Download the disk image from the same page, drag Wireshark to Applications, and allow the capture helper when asked.
Linux
Use your package manager, for example sudo apt install wireshark. Choose to let non-root users capture, then add yourself to the wireshark group and log in again.
Practice safely: use the official sample captures or capture your own home traffic while browsing. Open a file with File → Open.
2. Interface tour
| Area | What it does |
|---|---|
| Capture start screen | Lists network interfaces with a small activity graph. Double-click one to start capturing. |
| Display filter bar | Type a filter and press Enter to show only matching packets. Green means valid syntax; red means an error. |
| Packet list (top) | One row per packet: number, time, source, destination, protocol, length, info. |
| Packet details (middle) | Expandable layers: Frame, Ethernet, IP, TCP/UDP, then the application protocol. |
| Packet bytes (bottom) | Raw hex and text. Clicking a field in the details highlights its bytes. |
| Status bar | Shows packet counts, displayed vs captured, and profile. |
| Statistics menu | Conversations, Endpoints, Protocol Hierarchy, I/O Graphs. Great for a first overview of a large file. |
Colouring rules highlight packet types (for example, TCP problems and resets stand out). Colours help, but always read the details before drawing a conclusion.
3. Capture filters vs display filters
| Capture filter | Display filter | |
|---|---|---|
| When applied | Before capture starts | After capture, any time |
| Effect | Packets that do not match are never saved | Packets are only hidden; nothing is lost |
| Syntax | BPF, e.g. host 10.0.0.5 and port 53 | Wireshark fields, e.g. ip.addr == 10.0.0.5 && dns |
| Best for | Limiting file size on busy links | Everyday investigation |
Tip: beginners should capture everything they are allowed to, then use display filters. A too-narrow capture filter can silently drop evidence you needed.
4. Filter cheat table
Display filters
| Goal | Filter |
|---|---|
| Traffic to or from a host | ip.addr == 10.0.0.5 |
| Only from / only to | ip.src == 10.0.0.5 / ip.dst == 10.0.0.5 |
| A TCP or UDP port | tcp.port == 443 / udp.port == 53 |
| A protocol | dns, http, tls, icmp, arp |
| Combine | && (and), || (or), ! (not) |
| Hide noise | !(arp || dns) |
| New TCP connection attempts | tcp.flags.syn == 1 && tcp.flags.ack == 0 |
| TCP resets | tcp.flags.reset == 1 |
| Retransmissions | tcp.analysis.retransmission |
| One conversation | tcp.stream eq 3 |
| Text anywhere in a packet | frame contains "login" |
| HTTP POST requests | http.request.method == "POST" |
| HTTP errors | http.response.code >= 400 |
| DNS name contains text | dns.qry.name contains "example" |
| TLS Client Hello | tls.handshake.type == 1 |
Capture filters (BPF)
| Goal | Filter |
|---|---|
| One host | host 10.0.0.5 |
| A subnet | net 192.168.1.0/24 |
| A port | port 53 |
| TCP on port 80 | tcp port 80 |
| Exclude ARP | not arp |
| Source host only | src host 10.0.0.5 |
5. Following streams
A single conversation is split over many packets. Follow Stream stitches the payload back together so you can read it like a transcript.
- Click one packet in the conversation.
- Choose Analyze → Follow → TCP Stream (or right-click the packet). UDP, HTTP and TLS options also exist.
- Read the transcript: one colour for each direction. Wireshark applies a filter like
tcp.stream eq N, which you can clear afterwards.
Use it for: reading cleartext protocols such as HTTP or FTP, spotting commands, and seeing file names. Encrypted TLS content appears as unreadable data unless you hold the keys.
6. Spotting the TCP three-way handshake
| Step | Direction | Flags | Meaning |
|---|---|---|---|
| 1 | Client → Server | SYN | “I want to connect.” |
| 2 | Server → Client | SYN, ACK | “Agreed, and I acknowledge you.” |
| 3 | Client → Server | ACK | “Acknowledged. Connection open.” |
- Filter
tcp.flags.syn == 1to see steps 1 and 2; add&& tcp.flags.ack == 0for step 1 only. - The Info column shows
[SYN],[SYN, ACK],[ACK]. Wireshark shows relative sequence numbers starting at 0 to keep them readable. - A connection ends with FIN/ACK exchanges, or abruptly with RST.
- A SYN answered by RST usually means the port is closed. A SYN with no reply may mean a firewall silently dropped it.
7. DNS and HTTP analysis
DNS
- Filter
dns. Expand the packet to see the query name, type and answers. - Common types: A (IPv4), AAAA (IPv6), CNAME (alias), MX (mail), TXT (free text).
- Failed lookups:
dns.flags.rcode == 3shows NXDOMAIN (name does not exist). A few are normal; hundreds of random names are not. - Match query to answer using the transaction ID shown in both packets.
- Ask: which host asked? Is the domain one you expect? Does the answer point somewhere sensible?
HTTP
- Filter
http. Requests show a method (GET, POST), path and Host header; responses show a status code (200 OK, 404 Not Found, 500 error). http.request.method == "POST"finds submitted data such as forms.- Use File → Export Objects → HTTP to list files transferred in cleartext. Never open exported files from unknown captures on a normal machine.
- HTTPS hides the content, but the TLS Client Hello often reveals the server name. Try
tls.handshake.extensions_server_name.
8. Ten suspicious-traffic patterns
These are clues, not proof. Each has a harmless explanation too, so confirm with context before escalating.
| # | Pattern | What you see | Starter filter / tool | Possible innocent cause |
|---|---|---|---|---|
| 1 | Port scan | One host sends SYNs to many ports; many RSTs return | tcp.flags.syn == 1 && tcp.flags.ack == 0 | Authorised vulnerability scanner |
| 2 | Brute-force logins | Many repeated connections to SSH, RDP or FTP from one source | tcp.port == 22, ftp.response.code == 530 | Misconfigured script with old password |
| 3 | Beaconing | Small connections to one external host at near-regular intervals | Statistics → Conversations; check time deltas | Software update or monitoring agent |
| 4 | DNS tunnelling | Very long, random-looking subdomains and many TXT queries | dns.qry.name.len > 50 | Some CDNs and security tools use long names |
| 5 | Many NXDOMAIN replies | Bursts of lookups for non-existent random domains | dns.flags.rcode == 3 | Typos or stale configuration |
| 6 | Cleartext credentials | Passwords sent over HTTP or FTP | ftp.request.command == "PASS", HTTP POST | Legacy system (still a risk to fix) |
| 7 | Large outbound transfer | One internal host sending far more data out than normal | Statistics → Conversations, sort by bytes | Backup or cloud sync |
| 8 | ARP spoofing | Two MAC addresses claiming one IP; Wireshark warns of duplicate address | arp.duplicate-address-detected | Failover or virtual IP set-ups |
| 9 | Odd ports | Traffic on unusual ports often linked with remote-access tools | tcp.port in {4444 6667 31337} | Developer or game software |
| 10 | Oversized ICMP | Ping packets carrying large or unusual data | icmp && data.len > 64 | Network path testing |
Method: overview first (Protocol Hierarchy, Conversations), then filter, then follow the stream, then note times, hosts and evidence for your report.
9. Practice questions (tap to reveal)
Q1. Why might a capture filter be risky for a beginner?
It discards non-matching packets permanently, so useful evidence may never be saved. A display filter only hides packets.
Q2. Which filter shows only the first packet of new TCP connections?
tcp.flags.syn == 1 && tcp.flags.ack == 0
Q3. A host sends 500 SYNs to different ports in seconds. What could this be?
A port scan. Check whether it is an approved scanner before treating it as an attack.
Q4. Why can’t you read the page content in HTTPS traffic?
The payload is encrypted by TLS. You can still see metadata such as IPs, timing and often the server name.
Q5. What does an NXDOMAIN response mean?
The requested domain name does not exist. Large volumes of random NXDOMAINs can hint at malware searching for a server.
10. YouTube search links
- Wireshark tutorial for beginners
- Display vs capture filters
- TCP handshake in Wireshark
- DNS analysis in Wireshark
- Spotting suspicious traffic
11. One-screen revision summary
- Panes: list, details, bytes. Use Statistics for the big picture.
- Capture filter = before, BPF, drops packets. Display filter = after, hides only.
- Follow Stream turns packets into a readable conversation.
- Handshake: SYN, SYN-ACK, ACK. RST means refused or abrupt end.
- DNS: watch NXDOMAIN bursts and long odd names. HTTP: methods, status codes, exported objects.
- Suspicious: scans, brute force, beacons, tunnelling, cleartext passwords, big uploads, ARP clashes, odd ports, big pings.
- Always: get permission, protect captures, confirm context.
Related pages
Educational summary for learners; not affiliated with Google or Coursera. Verify details against official Wireshark documentation. Last reviewed: October 2026.
