Skip to content
Back to blog
Network Security
2026-05-15 8 min read

A Student's Guide to Network Traffic Analysis with Wireshark

Learn how to capture, filter, and analyze network packets using Wireshark, the essential skill for any aspiring cybersecurity professional.

Wireshark
Packet Analysis
Networking

Wireshark is the world's most popular network protocol analyzer. Whether you're troubleshooting a network issue or investigating a security incident, understanding how to read packet captures is a fundamental skill in cybersecurity.

Getting Started

Download Wireshark from wireshark.org and install it on your machine. On Linux, you can install it with:

sudo apt update
sudo apt install wireshark

When you launch Wireshark, you'll see a list of network interfaces. Select the one you want to monitor (e.g., eth0 or wlan0) and click the shark fin icon to start capturing.

Understanding the Interface

Wireshark's main window is divided into three panes:

  • Packet List, A summary of each captured packet (time, source, destination, protocol, info).
  • Packet Details, A tree-view breakdown of the selected packet's protocol layers.
  • Packet Bytes, The raw hexadecimal and ASCII data of the selected packet.

Essential Display Filters

Display filters let you narrow down the packets you see. Here are some commonly used ones:

# Show only HTTP traffic
http

# Filter by IP address
ip.addr == 192.168.1.100

# Show only DNS queries
dns

# Filter by TCP port
tcp.port == 443

# Show only packets with a specific flag
tcp.flags.syn == 1 && tcp.flags.ack == 0

Practical Exercise: Analyzing an HTTP Session

  1. Start a capture on your active interface.
  2. Open a browser and visit an HTTP website (not HTTPS, so you can see the traffic in plain text).
  3. Stop the capture.
  4. Apply the filter http.
  5. Right-click on a GET request and select Follow → TCP Stream.
  6. You'll see the full HTTP request and response, including headers and body content.

Saving and Sharing Captures

You can save your capture as a .pcap or .pcapng file for later analysis or to share with your team. Go to File → Save As and choose your format.

Tips for Beginners

  • Always capture on your own network or with explicit permission.
  • Use capture filters to reduce file size when monitoring high-traffic networks.
  • Learn the OSI model, it makes understanding packet layers much easier.
  • Practice with sample captures from wiki.wireshark.org/SampleCaptures.