tshark Commands Reference

Command-line Wireshark for TLS-focused packet analysis. Complements tcpdump when you need protocol decoding.

📦 Installation

brew install wireshark
# Debian/Ubuntu: sudo apt install tshark

📡 Capture TLS traffic

# Live capture on port 443
sudo tshark -i eth0 -f "tcp port 443" -w tls.pcapng

# Read a capture
tshark -r tls.pcapng

# Show only TLS handshake messages
tshark -r tls.pcapng -Y "tls.handshake.type"

🔍 Useful display filters

tshark -r tls.pcapng -Y "tls.handshake.type == 1"   # ClientHello
tshark -r tls.pcapng -Y "tls.handshake.type == 11"  # Certificate
tshark -r tls.pcapng -Y "tls.alert_message"
tshark -r tls.pcapng -Y "http2 or http" -T fields -e frame.time -e ip.src -e tls.handshake.extensions_server_name

🔑 Decrypt with SSLKEYLOGFILE

# Browser/app writes secrets (NSS SSLKEYLOGFILE format)
export SSLKEYLOGFILE=/tmp/sslkeys.log

# Point tshark at the key log
tshark -r tls.pcapng -o tls.keylog_file:/tmp/sslkeys.log -Y http

Only works for TLS sessions whose secrets were logged. Never share key logs from production.

🔗 See Also