Wireshark
Free, open-source network protocol analyser for capturing and inspecting traffic in detail, live or from saved capture files.
- Category
- Defensive Security & Monitoring
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- Licence
- Open source
- Reviewed
- Last reviewed 24 September 2026
What it is
Wireshark is a widely used network protocol analyser, developed as an open-source project since 1998.
What it helps with
Capturing live traffic or opening saved captures; inspecting hundreds of protocols down to individual fields; filtering with a powerful display-filter language; analysing VoIP; and decrypting protocols such as TLS when the keys are available. It is used for troubleshooting, incident investigation and learning how protocols work.
Who it's for
Network engineers, incident responders and forensic analysts, security researchers, and students.
Worth knowing
Capturing traffic may require administrator privileges and a capture driver such as Npcap on Windows. Capture only traffic you are authorised to inspect.