TechKnowSurge
Cisco CCST Networking 5.2 CompTIA Network+ 3.2 Cisco CyberOps Associate 4.6 CompTIA Network+ 5.5
VideoNetworkFree

Capturing Data with Wireshark

Wireshark basics are covered through a live demonstration of selecting a network interface and capturing real traffic from an Ethernet connection on a test network.

Complete this video to capture a CTF flag worth 1 point.

About this video

Network traffic capture using Wireshark begins with understanding the launch interface, which allows users to either open previously saved capture files or start a new capture session. Before capturing begins, Wireshark displays all available network interfaces on the machine, showing live traffic activity for each one so the user can identify which interface is most relevant to monitor. The machine in this demonstration includes multiple interfaces: two Ethernet adapters, a Wi-Fi adapter, Bluetooth, and several virtual network adapters associated with VirtualBox. Rather than capturing from the primary Ethernet connection used for remote desktop access, a secondary Ethernet interface connected to an isolated test network is selected. Once the capture starts on that interface, web traffic is generated through a browser to populate the capture with real data, establishing a working baseline for further analysis.

What you'll learn

What's covered

Capturing Data with Wireshark

Aligned to

Cisco CCST Networking
5.2 Perform a packet capture with Wireshark and save it to a file
CompTIA Network+
3.2 Given a scenario, use network monitoring technologies
5.5 Given a scenario, use the appropriate tool or protocol to solve networking issues
Cisco CyberOps Associate
4.6 Extract files from a TCP stream when given a PCAP file and Wireshark

Key terms

Network Interface Card
NIC
A hardware component that connects a computer to a network.
Packet
A unit of data formatted for transmission over a network, containing a header, payload, and sometimes a trailer.
Wireshark
Wireshark is an open-source network protocol analyzer that captures and interactively displays packet-level traffic, used by security professionals for network forensics, vulnerability research, and incident investigation.
Packet Capture
PCAP
Packet Capture is the process of intercepting and recording network packets as they traverse a network interface, used in network forensics, intrusion analysis, protocol troubleshooting, and incident response investigations.

Topics

Wireshark Packet Capture Network Traffic Analysis Network Interfaces Ethernet Networking

Transcript

We're just going to start capturing some data and then I'll stop capturing data. It's pretty straightforward.

The launch screen

What I'm going to do is open up the program, and the program is open now. Just a little bit about this launching menu here: I can open up any prior captures — I've got some saved captures here — so I could open up any prior captures, or I could capture some new data here.

What I want to do is capture new data here. What it's showing me here is all of the different interfaces that I have. As I mentioned, it's going to capture data from a network interface card, and I have several on this machine. One of them is just the standard ethernet. I've got a second ethernet that's plugged in. I also have the Wi-Fi. This also has Bluetooth on it, so you'll probably see those. And then I have a few local area connections, some of which are associated with — because I've got an emulator on here, or not an emulator but a virtualization software on here, VirtualBox — so some of these are created for that purpose.

Picking an interface and capturing

So really, all I care about is just the network connection that I want to monitor. In this case right here I'm going to be monitoring this ethernet connection, and as you can see it shows you some of the traffic that's going across it. Not a lot of traffic is going across it. A lot more traffic is going across this ethernet 2 — that's what I'm remoted in with, that's what I'm using to RDP into it — but I want to capture this ethernet card, which is on my test network.

So all I'm going to do is double click on this ethernet to open it up, and it's going to start capturing the data. Now, as we saw, it's not a real active ethernet card here, and there's not a lot of traffic that's going on here, so I'm going to generate some traffic here. I'll move this off to the side here and we'll just keep it right there, and I am going to open up Chrome here.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →