官术网_书友最值得收藏!

Wireshark command-line utilities

When you install Wireshark, a range of command-line tools also gets installed, including:

  • capinfos.exe: This prints information about trace files
  • dumpcap.exe: This captures packets and saves to a libpcap format file
  • editcap.exe: This splits a trace file, alters timestamps, and removes duplicate packets
  • mergecap.exe: This merges two or more packet files into one file
  • rawshark.exe: This reads a stream of packets and prints field descriptions
  • text2pcap.exe: This reads an ASCII hex dump and writes a libpcap file
  • tshark.exe: This captures network packets or displays data from a saved trace file

The Wireshark.exe file launches the GUI version you're familiar with, but you can also launch Wireshark from the command line with a number of parameters; type Wireshark –h for a list of options and/or create shortcuts to launch Wireshark with any of those options.

Note

It is very helpful to add the Wireshark program directory to your system's PATH statement so that you can execute any of the command-line utilities from any working directory.

主站蜘蛛池模板: 贵溪市| 沙洋县| 南通市| 始兴县| 贵州省| 偃师市| 高要市| 凯里市| 丽江市| 海宁市| 乌兰浩特市| 昌乐县| 巴塘县| 双流县| 论坛| 阳曲县| 赣榆县| 阜城县| 甘肃省| 襄樊市| 奎屯市| 马尔康县| 余江县| 乐亭县| 察哈| 时尚| 玛多县| 惠来县| 丰镇市| 晋宁县| 邓州市| 莒南县| 永胜县| 灵石县| 舒兰市| 锡林浩特市| 广德县| 六枝特区| 涟水县| 芜湖市| 长海县|