twitter: @sw4pn1lp
GUI of Wireshark Main Window
Ctrl + . Move to the next packet of the conversation.
Ctrl + , Move to the Previous packet of the conversation.
Left Arrow In the packet detail, closes the selected tree item. If it’s already closed, jumps to the parent node.
Right Arrow In the packet detail, opens the selected tree item.
(For this Excersise please, you can download PCAP file from here)
Menu bar mostly used in starting the actions
Main Toolbar contains some of the frequently used items from Menu Bar.
User cannot customized this bar.
The filter toolbar lets you quickly edit and apply display filters.
It displays all the packets in the current capture file.
First Packet in Conversation
Last Packet in Conversation
Request - Response
Packet detaails pane shows more details about current packet.
Generated Fields These fields are not part of packet. wireshark itself will add them. This field is enclosed in square brackets [ ]. Generated information includes response times, TCP analysis, GeoIP information, and checksum validation.
Links If wireshark detects any link to other packet, it will generate link.
This Pane shows the Packet description in hexdump style.
This bar shows Informational messages
« Intro to wireshark | Capturing Packets » |