TechKnowSurge
Cisco CCST Networking 5.2 Cisco CyberOps Associate 4.6
VideoNetworkFree

Other Basic Features

Wireshark's toolbar, capture controls, and display settings can be customized to make packet analysis faster and more efficient. Adjusting text size, managing capture files, and toggling interface panels like the packet bytes view helps tailor the workspace to your needs.

Complete this video to capture a CTF flag worth 1 point.

About this video

Wireshark includes a range of interface features designed to make packet capture and analysis more efficient and easier to navigate. The toolbar buttons at the top of the window each serve a specific purpose, and hovering over any button displays a tooltip that identifies its function — a useful reference when learning the layout. Text size within the main window can be scaled up or down directly from the toolbar, allowing analysts to adjust the display to a comfortable reading level. Capture management is handled through dedicated toolbar controls that let users start a new capture session, stop an active one, and close or reopen previously saved capture files. When starting a new capture, Wireshark will prompt to save any unsaved data from the previous session before proceeding, helping prevent accidental data loss. The View menu provides additional control over the workspace layout. Panels such as the main toolbar, filter bar, status bar, and packet bytes pane can each be toggled independently. Removing the packet bytes pane, which displays raw binary data, frees up vertical space and allows more room to examine packet details — particularly useful when working through large captures or complex protocol hierarchies.

What you'll learn

What's covered

Wireshark UI Tips

Aligned to

Cisco CCST Networking
5.2 Perform a packet capture with Wireshark and save it to a file
Cisco CyberOps Associate
4.6 Extract files from a TCP stream when given a PCAP file and Wireshark

Key terms

Packet
A unit of data formatted for transmission over a network, containing a header, payload, and sometimes a trailer.
Wireshark
Wireshark is an open-source network protocol analyzer that captures and interactively displays packet-level traffic, used by security professionals for network forensics, vulnerability research, and incident investigation.
Packet Capture
PCAP
Packet Capture is the process of intercepting and recording network packets as they traverse a network interface, used in network forensics, intrusion analysis, protocol troubleshooting, and incident response investigations.
Packet Bytes Pane
The bottom-right section of the Wireshark interface that displays the raw binary and ASCII representation of the selected packet's data.

Topics

Wireshark Packet Analysis Network Traffic Capture Display Configuration Networking

Transcript

Let's cover a few more elements that I like to use, just to make it a little more handy to use Wireshark.

Finding out what the buttons do

Number one is anything with these buttons up here. If I want to know what it means — for instance, if I want to know what this is — I can hover above it, and it says enlarge the main window text. So if I want to make it a little bit larger so I can see it, I can click on that, or maybe I can shrink it, so I can dial it in to the right size.

Closing and reopening a capture

Another thing here that I'll use occasionally is this close this captured file. So I'm going to close this out, and then it will close it out. Or if I want to reopen it, since I saved it before, then I can reopen it by double clicking it.

Starting and stopping a capture

Another thing that I do quite often is I want to capture something new, so I'll hit this capture button right here, start capturing packets, and then it's going to start. If you hadn't saved the last file, then at this point in time it would ask you to save it, but I'd already saved it, so that's fine.

Let's generate some traffic again so we've got some traffic to work with, and then maybe I want to stop that capture there, so then I'll stop it. So there is the stop.

Removing panes from the view

Another thing too is that I really like to see these binary numbers down here. I think they are kind of cool, but I mean, for the most part it's just ones and zeros — really, what does it mean? So another thing I can do is click on view and remove that from here. In fact, I can remove the main toolbar, the filter bar, the status bar, I can remove any of those. Or in this case right here I want to remove the packet bytes, and then that will give me a little more space that I can actually dig into these packets.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →