官术网_书友最值得收藏!

Wireshark command-line utilities

When you install Wireshark, a range of command-line tools also gets installed, including:

  • capinfos.exe: This prints information about trace files
  • dumpcap.exe: This captures packets and saves to a libpcap format file
  • editcap.exe: This splits a trace file, alters timestamps, and removes duplicate packets
  • mergecap.exe: This merges two or more packet files into one file
  • rawshark.exe: This reads a stream of packets and prints field descriptions
  • text2pcap.exe: This reads an ASCII hex dump and writes a libpcap file
  • tshark.exe: This captures network packets or displays data from a saved trace file

The Wireshark.exe file launches the GUI version you're familiar with, but you can also launch Wireshark from the command line with a number of parameters; type Wireshark –h for a list of options and/or create shortcuts to launch Wireshark with any of those options.

Note

It is very helpful to add the Wireshark program directory to your system's PATH statement so that you can execute any of the command-line utilities from any working directory.

主站蜘蛛池模板: 安庆市| 阿拉善左旗| 布拖县| 岳池县| 凌源市| 微博| 台南市| 新余市| 屯门区| 济阳县| 隆安县| 金沙县| 莎车县| 诸暨市| 临漳县| 九台市| 乌兰察布市| 邹平县| 河津市| 德格县| 房产| 扎兰屯市| 平远县| 武穴市| 颍上县| 天长市| 南陵县| 罗山县| 高邮市| 阜南县| 斗六市| 仁布县| 益阳市| 宁乡县| 苍山县| 海阳市| 增城市| 黄龙县| 盐池县| 阿克陶县| 南汇区|