From the course: Wireshark: Malware and Forensics

Unlock the full course today

Join today to access over 22,400 courses taught by industry experts or purchase this course individually.

Tshark

Tshark - Wireshark Tutorial

From the course: Wireshark: Malware and Forensics

Start my 1-month free trial

Tshark

- [Narrator] Most network administrators are familiar with Wireshark. It has a rich graphical interface with many built in tools, however you really should try Tshark. It's a lightweight command-line tool. You'll want to go into the command-line interface and run as administrator. I've enlarged the font so you can see it a little bit better, but as you can see, here up at the top, administrator command prompt. And that's so you can write the files without any problems. Now I need to get to Wireshark. First I want to go to the directory, so I'll need to change directory to program files. Because there's more than eight characters, I'll have to use quotes. Now we'll change the directory now to Wireshark. And that's the directory where Tshark resides. Now I'll need to build my command. It's important to know what interface you'll need. If you have multiple interfaces, find out which one is active using IP config. Alright, let's build my command. We'll start with Tshark, and then I'll say…

Contents