tshark Commands Reference
Command-line Wireshark for TLS-focused packet analysis. Complements tcpdump when you need protocol decoding.
📦 Installation
brew install wireshark
# Debian/Ubuntu: sudo apt install tshark📡 Capture TLS traffic
# Live capture on port 443
sudo tshark -i eth0 -f "tcp port 443" -w tls.pcapng
# Read a capture
tshark -r tls.pcapng
# Show only TLS handshake messages
tshark -r tls.pcapng -Y "tls.handshake.type"🔍 Useful display filters
tshark -r tls.pcapng -Y "tls.handshake.type == 1" # ClientHello
tshark -r tls.pcapng -Y "tls.handshake.type == 11" # Certificate
tshark -r tls.pcapng -Y "tls.alert_message"
tshark -r tls.pcapng -Y "http2 or http" -T fields -e frame.time -e ip.src -e tls.handshake.extensions_server_name🔑 Decrypt with SSLKEYLOGFILE
# Browser/app writes secrets (NSS SSLKEYLOGFILE format)
export SSLKEYLOGFILE=/tmp/sslkeys.log
# Point tshark at the key log
tshark -r tls.pcapng -o tls.keylog_file:/tmp/sslkeys.log -Y httpOnly works for TLS sessions whose secrets were logged. Never share key logs from production.