1 min read 128 words Updated Sep 12, 2026 Created Sep 12, 2026

tshark is the command counterpart to Wireshark.
It comes with wireshark and should be available if Wireshark is installed

example quick search for flag

tshark -r capture.pcapng -Y 'frame contains "SKY-"' -T fields -e frame.number -e data

tshark — the command-line version of Wireshark for capturing/reading packets

-r capture.pcapng — read from the file capture.pcapng instead of live capturing

-Y 'frame contains "SKY-"' — display filter (like Wireshark's filter bar); only process frames where the raw content contains the string SKY-

-T fields — sets the output format to fields mode, meaning only print the specific fields you ask for (rather than the default summary line)

-e frame.number — extract the frame number field

-e data — extract the raw data field (the payload bytes)