Welcome to Shark Week: A Guide for Getting Started with Wireshark and TShark
ID: 69717fc3-08e2-5c90-b4e7-971f37d31d59
STIX ID: report--69717fc3-08e2-5c90-b4e7-971f37d31d59
Feed Name: Black Hills Infosec Blog
This article is a hands-on primer for analyzing packet captures with Wireshark and TShark, detailing recommended settings (time display, name resolution), capture and output strategies, the difference between capture and display filters, following TCP streams, exporting HTTP objects, and extracting fields on the command line for aggregation and telemetry. It also stresses OPSEC (e.g., avoiding reverse DNS lookups), keeping tools updated, and leveraging TShark to scale network forensics beyond the GUI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
