Jump to navigation Jump to search
tshark is the equivalent of Wireshark in based on the Command Line Interface (CLI).
# apt-get install tshark
tshark -R 'filter' -r capture.pcap
Some common filters:
- smtp.req.command contains "RCPT"
- contains (ex: dns contains windows)
- http://www.wireshark.org/docs/dfref/: Tshark filters are the same as Wireshark filters. The complete list by protocol is available online