Wireshark

Wireshark

Wireshark (Netzwerk-Analysewerkzeug)

Wireshark is the most widely used open-source tool for analysing network traffic. It captures data packets and dissects them down to the detail, so that communication can be traced step by step. In network forensics, troubleshooting and protocol analysis it is a standard instrument.

History & facts. Wireshark (formerly Ethereal) shows network traffic at the packet level and understands a very large number of protocols, which it dissects into readable fields. It works both on live traffic and on stored packet captures (PCAP). This makes it possible to examine precisely who communicated with whom about what — from network troubleshooting to the forensic reconstruction of a data outflow. Outlook & recommendation. Wireshark is indispensable for the deep analysis of individual traffic captures; for continuous, broad monitoring of large networks, tools such as Zeek or Suricata are more suitable. Two practical notes: first, only what was previously recorded can be analysed — recording is the actual bottleneck. Second, increasing encryption shifts the gain in insight from content towards metadata and patterns.
Wireshark — Wireshark