Get Notified when the Software is Updated

Wireshark is the world’s leading network protocol analyzer, trusted by professionals for network troubleshooting, analysis, software and communication protocol development, and educational purposes. It provides deep insight into network traffic, helping users diagnose issues and optimize performance efficiently.
This tool captures and analyzes live network traffic, delivering real-time interactive insights. It is cross-platform, built with the GTK+ interface, and powered by the pcap library for fast packet capture.
Wireshark is recognized as the de facto and, in many cases, the de jure standard across industries and educational institutions. While it functions similarly to tcpdump, it stands out with its intuitive graphical interface and advanced, built-in filtering and sorting capabilities for streamlined network analysis.
Wireshark enables users to place network interfaces that support promiscuous mode into that state, allowing them to view all network traffic on the interface, not just packets addressed to the interface’s configured addresses or broadcast and multicast traffic. This functionality gives users a detailed perspective on network operations for advanced analysis.
However, when capturing traffic in promiscuous mode on a network switch port, not all traffic passing through the switch will be forwarded to the capture port. So, capturing in promiscuous mode will not necessarily capture all traffic on the network. Port mirroring or various network taps extend capture to any point on the network. Simple passive taps are extremely resistant to malware tampering.
Wireshark Features:
- Deep inspection of hundreds of protocols, with more being added all the time
- Live capture and offline analysis
- Standard three-pane packet browser
- Multi-platform. Runs on Windows, Linux, OS X, Solaris, FreeBSD, NetBSD, and many others
- Can browse the captured network data via a GUI or the TTY-mode TShark utility
- The most powerful display filters in the industry
- Rich VoIP analysis
- Read and write various capture file formats, including tcpdump (libpcap), Pcap NG, Catapult DCT2000, and Cisco Secure IDS iplog. Microsoft Network Monitor, Network General Sniffer, Sniffer Pro, and NetXray. Also, Network Instruments Observer, NetScreen Snoop, Novell LANalyzer, RADCOM WAN/LAN Analyzer, and Shomiti/Finisar Surveyor. Tektronix K12xx, Visual Networks Visual UpTime, WildPackets EtherPeek/TokenPeek/AiroPeek, and many others
- Capture files compressed with gzip can be decompressed on the fly
- Can read live data from Ethernet, IEEE 802.11, PPP/HDLC, ATM, Bluetooth, USB, Token Ring, Frame Relay, FDDI, and others
- Decryption support for many protocols. Including IPsec, ISAKMP, Kerberos, SNMPv3, SSL/TLS, WEP, and WPA/WPA2
- Applies the coloring rules to the packet list for quick, intuitive analysis
- Allows the Output to export to XML, PostScript, CSV, or plain text
Wireshark – Pros & Cons
| Pros | Cons |
|---|---|
| ✓ Captures live network traffic and supports offline packet analysis, making it useful for both real-time troubleshooting and reviewing saved captures. | ✗ Promiscuous mode does not guarantee visibility into all traffic on a switched network; port mirroring or network taps may be required for broader capture coverage. |
| ✓ The software provides deep inspection of hundreds of network protocols and continues to add support for additional protocols over time. | ✗ Its extensive protocol inspection, filtering, and packet-analysis capabilities are geared toward detailed network analysis rather than simple traffic monitoring. |
| ✓ Includes powerful display filters, packet coloring rules, and a three-pane packet browser for detailed traffic analysis. | ✗ The effectiveness of some traffic analysis depends on access to the relevant network interface and capture point, which can affect which packets are available for inspection. |
| ✓ Supports numerous capture formats and can read traffic from Ethernet, Wi-Fi, Bluetooth, USB, and other network technologies. | ✗ The Windows download is available in separate x64 and ARM64 builds, so users need to select the installer that matches their system architecture. |
| ✓ Offers broad platform support, including Windows, Linux, macOS, FreeBSD, and NetBSD, with both graphical and TShark command-line access to captured data. | ✗ The feature set includes extensive protocol support, multiple capture formats, decryption capabilities, filtering, and export options, which can make the application more complex for users new to packet analysis. |
Frequently Asked Questions
Why is Wireshark not showing my network interface?
On Windows, live packet capture depends on the Npcap capture driver and support from the underlying network adapter. If an interface is missing, check that Npcap is installed and that the adapter and driver support packet capture.
Can Wireshark capture localhost traffic?
Yes. On Windows, Wireshark can capture localhost traffic through Npcap’s loopback capture support. Select the loopback capture interface when you need to inspect traffic exchanged through the local machine rather than through a physical network adapter.
Why is Wireshark not capturing Wi-Fi packets?
Wi-Fi capture on Windows depends on the wireless adapter, its driver, and Npcap’s monitor-mode support. If packets are missing, this may be because the adapter does not support the required capture mode or because limitations on promiscuous or monitor mode prevent the expected traffic from being captured.
What is the difference between Wireshark and tcpdump?
Both tools support network packet capture and analysis, but Wireshark offers detailed graphical inspection and filtering, while tcpdump is a command-line tool designed for fast and scriptable packet captures. They can also be used together, with tcpdump capturing packets and Wireshark opening the resulting capture files for graphical analysis.
Official Homepage – https://www.wireshark.org
Runs on Windows, Linux, OS X, FreeBSD, NetBSD, and many others.
Size: 94.3 MB
DOWNLOAD Wireshark 4.6.8 for Windows 64-bit
DOWNLOAD Wireshark 4.6.8 for Windows ARM64
DOWNLOAD Wireshark 4.6.8 Portable for Windows 64-bit
DOWNLOAD Wireshark 4.6.8 for macOS ARM 64-bit
DOWNLOAD Wireshark 4.6.8 for macOS Intel 64-bit
DOWNLOAD Wireshark 4.6.8 Source Code
DOWNLOAD 4.4.18 for Windows x64
DOWNLOAD 4.4.18 for Windows ARM64
DOWNLOAD 4.4.18 Portable for Windows x64
DOWNLOAD 4.4.18 Portable for Windows ARM64
DOWNLOAD 4.4.18 for macOS ARM64
