官术网_书友最值得收藏!

Wireshark command-line utilities

When you install Wireshark, a range of command-line tools also gets installed, including:

  • capinfos.exe: This prints information about trace files
  • dumpcap.exe: This captures packets and saves to a libpcap format file
  • editcap.exe: This splits a trace file, alters timestamps, and removes duplicate packets
  • mergecap.exe: This merges two or more packet files into one file
  • rawshark.exe: This reads a stream of packets and prints field descriptions
  • text2pcap.exe: This reads an ASCII hex dump and writes a libpcap file
  • tshark.exe: This captures network packets or displays data from a saved trace file

The Wireshark.exe file launches the GUI version you're familiar with, but you can also launch Wireshark from the command line with a number of parameters; type Wireshark –h for a list of options and/or create shortcuts to launch Wireshark with any of those options.

Note

It is very helpful to add the Wireshark program directory to your system's PATH statement so that you can execute any of the command-line utilities from any working directory.

主站蜘蛛池模板: 天水市| 温宿县| 章丘市| 长垣县| 横峰县| 项城市| 阳江市| 巩留县| 南溪县| 太原市| 浮山县| 云龙县| 景泰县| 西平县| 东光县| 潞西市| 涡阳县| 东辽县| 田阳县| 广饶县| 古田县| 保定市| 麻江县| 宁都县| 福清市| 明溪县| 莱州市| 沁源县| 东城区| 轮台县| 阳高县| 乌拉特中旗| 辰溪县| 兖州市| 清新县| 平南县| 汉川市| 天祝| 华宁县| 上杭县| 博乐市|