Wireshark Tutorial for Beginners: Capture, Filter and Spot Suspicious Traffic

    A practical walk-through of Wireshark: installing it, finding your way around, using filters, following streams, reading the TCP handshake, analysing DNS and HTTP, and recognising ten suspicious-traffic patterns. A filter cheat table is included.

    Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations are original. Capture traffic only on networks you own or have written permission to monitor, and treat captures as sensitive because they can contain passwords and personal data. See the official Wireshark documentation for full details.

    1. Installation

    Windows

    Download the installer from wireshark.org. It offers to install Npcap, the capture driver. Accept it.

    macOS

    Download the disk image from the same page, drag Wireshark to Applications, and allow the capture helper when asked.

    Linux

    Use your package manager, for example sudo apt install wireshark. Choose to let non-root users capture, then add yourself to the wireshark group and log in again.

    Practice safely: use the official sample captures or capture your own home traffic while browsing. Open a file with File → Open.

    2. Interface tour

    AreaWhat it does
    Capture start screenLists network interfaces with a small activity graph. Double-click one to start capturing.
    Display filter barType a filter and press Enter to show only matching packets. Green means valid syntax; red means an error.
    Packet list (top)One row per packet: number, time, source, destination, protocol, length, info.
    Packet details (middle)Expandable layers: Frame, Ethernet, IP, TCP/UDP, then the application protocol.
    Packet bytes (bottom)Raw hex and text. Clicking a field in the details highlights its bytes.
    Status barShows packet counts, displayed vs captured, and profile.
    Statistics menuConversations, Endpoints, Protocol Hierarchy, I/O Graphs. Great for a first overview of a large file.

    Colouring rules highlight packet types (for example, TCP problems and resets stand out). Colours help, but always read the details before drawing a conclusion.

    3. Capture filters vs display filters

    Capture filterDisplay filter
    When appliedBefore capture startsAfter capture, any time
    EffectPackets that do not match are never savedPackets are only hidden; nothing is lost
    SyntaxBPF, e.g. host 10.0.0.5 and port 53Wireshark fields, e.g. ip.addr == 10.0.0.5 && dns
    Best forLimiting file size on busy linksEveryday investigation

    Tip: beginners should capture everything they are allowed to, then use display filters. A too-narrow capture filter can silently drop evidence you needed.

    4. Filter cheat table

    Display filters
    GoalFilter
    Traffic to or from a hostip.addr == 10.0.0.5
    Only from / only toip.src == 10.0.0.5 / ip.dst == 10.0.0.5
    A TCP or UDP porttcp.port == 443 / udp.port == 53
    A protocoldns, http, tls, icmp, arp
    Combine&& (and), || (or), ! (not)
    Hide noise!(arp || dns)
    New TCP connection attemptstcp.flags.syn == 1 && tcp.flags.ack == 0
    TCP resetstcp.flags.reset == 1
    Retransmissionstcp.analysis.retransmission
    One conversationtcp.stream eq 3
    Text anywhere in a packetframe contains "login"
    HTTP POST requestshttp.request.method == "POST"
    HTTP errorshttp.response.code >= 400
    DNS name contains textdns.qry.name contains "example"
    TLS Client Hellotls.handshake.type == 1
    Capture filters (BPF)
    GoalFilter
    One hosthost 10.0.0.5
    A subnetnet 192.168.1.0/24
    A portport 53
    TCP on port 80tcp port 80
    Exclude ARPnot arp
    Source host onlysrc host 10.0.0.5

    5. Following streams

    A single conversation is split over many packets. Follow Stream stitches the payload back together so you can read it like a transcript.

    1. Click one packet in the conversation.
    2. Choose Analyze → Follow → TCP Stream (or right-click the packet). UDP, HTTP and TLS options also exist.
    3. Read the transcript: one colour for each direction. Wireshark applies a filter like tcp.stream eq N, which you can clear afterwards.

    Use it for: reading cleartext protocols such as HTTP or FTP, spotting commands, and seeing file names. Encrypted TLS content appears as unreadable data unless you hold the keys.

    6. Spotting the TCP three-way handshake

    StepDirectionFlagsMeaning
    1Client → ServerSYN“I want to connect.”
    2Server → ClientSYN, ACK“Agreed, and I acknowledge you.”
    3Client → ServerACK“Acknowledged. Connection open.”
    • Filter tcp.flags.syn == 1 to see steps 1 and 2; add && tcp.flags.ack == 0 for step 1 only.
    • The Info column shows [SYN], [SYN, ACK], [ACK]. Wireshark shows relative sequence numbers starting at 0 to keep them readable.
    • A connection ends with FIN/ACK exchanges, or abruptly with RST.
    • A SYN answered by RST usually means the port is closed. A SYN with no reply may mean a firewall silently dropped it.

    7. DNS and HTTP analysis

    DNS
    • Filter dns. Expand the packet to see the query name, type and answers.
    • Common types: A (IPv4), AAAA (IPv6), CNAME (alias), MX (mail), TXT (free text).
    • Failed lookups: dns.flags.rcode == 3 shows NXDOMAIN (name does not exist). A few are normal; hundreds of random names are not.
    • Match query to answer using the transaction ID shown in both packets.
    • Ask: which host asked? Is the domain one you expect? Does the answer point somewhere sensible?
    HTTP
    • Filter http. Requests show a method (GET, POST), path and Host header; responses show a status code (200 OK, 404 Not Found, 500 error).
    • http.request.method == "POST" finds submitted data such as forms.
    • Use File → Export Objects → HTTP to list files transferred in cleartext. Never open exported files from unknown captures on a normal machine.
    • HTTPS hides the content, but the TLS Client Hello often reveals the server name. Try tls.handshake.extensions_server_name.

    8. Ten suspicious-traffic patterns

    These are clues, not proof. Each has a harmless explanation too, so confirm with context before escalating.

    #PatternWhat you seeStarter filter / toolPossible innocent cause
    1Port scanOne host sends SYNs to many ports; many RSTs returntcp.flags.syn == 1 && tcp.flags.ack == 0Authorised vulnerability scanner
    2Brute-force loginsMany repeated connections to SSH, RDP or FTP from one sourcetcp.port == 22, ftp.response.code == 530Misconfigured script with old password
    3BeaconingSmall connections to one external host at near-regular intervalsStatistics → Conversations; check time deltasSoftware update or monitoring agent
    4DNS tunnellingVery long, random-looking subdomains and many TXT queriesdns.qry.name.len > 50Some CDNs and security tools use long names
    5Many NXDOMAIN repliesBursts of lookups for non-existent random domainsdns.flags.rcode == 3Typos or stale configuration
    6Cleartext credentialsPasswords sent over HTTP or FTPftp.request.command == "PASS", HTTP POSTLegacy system (still a risk to fix)
    7Large outbound transferOne internal host sending far more data out than normalStatistics → Conversations, sort by bytesBackup or cloud sync
    8ARP spoofingTwo MAC addresses claiming one IP; Wireshark warns of duplicate addressarp.duplicate-address-detectedFailover or virtual IP set-ups
    9Odd portsTraffic on unusual ports often linked with remote-access toolstcp.port in {4444 6667 31337}Developer or game software
    10Oversized ICMPPing packets carrying large or unusual dataicmp && data.len > 64Network path testing

    Method: overview first (Protocol Hierarchy, Conversations), then filter, then follow the stream, then note times, hosts and evidence for your report.

    9. Practice questions (tap to reveal)

    Q1. Why might a capture filter be risky for a beginner?

    It discards non-matching packets permanently, so useful evidence may never be saved. A display filter only hides packets.

    Q2. Which filter shows only the first packet of new TCP connections?

    tcp.flags.syn == 1 && tcp.flags.ack == 0

    Q3. A host sends 500 SYNs to different ports in seconds. What could this be?

    A port scan. Check whether it is an approved scanner before treating it as an attack.

    Q4. Why can’t you read the page content in HTTPS traffic?

    The payload is encrypted by TLS. You can still see metadata such as IPs, timing and often the server name.

    Q5. What does an NXDOMAIN response mean?

    The requested domain name does not exist. Large volumes of random NXDOMAINs can hint at malware searching for a server.

    10. YouTube search links

    11. One-screen revision summary

    • Panes: list, details, bytes. Use Statistics for the big picture.
    • Capture filter = before, BPF, drops packets. Display filter = after, hides only.
    • Follow Stream turns packets into a readable conversation.
    • Handshake: SYN, SYN-ACK, ACK. RST means refused or abrupt end.
    • DNS: watch NXDOMAIN bursts and long odd names. HTTP: methods, status codes, exported objects.
    • Suspicious: scans, brute force, beacons, tunnelling, cleartext passwords, big uploads, ARP clashes, odd ports, big pings.
    • Always: get permission, protect captures, confirm context.

    ← Back to hub

    Educational summary for learners; not affiliated with Google or Coursera. Verify details against official Wireshark documentation. Last reviewed: October 2026.