Frequently Asked Questions
Legal, security, licensing, and usage answers for Wireshark users and IT teams.
Click a question to expand. One answer is shown at a time.
General
Wireshark runs on Windows, macOS, Linux, and UNIX systems. It can be built from source on additional platforms. Current stable release is 4.6.6 with old stable 4.4.16 available for migration scenarios. See the Download page for platform installers.
Yes. Wireshark is free software under the GNU General Public License version 2. There is no license fee and no feature-limited demo. The Wireshark Foundation supports development through donations and sponsorships.
Yes. The GPL allows commercial use. If you modify and distribute Wireshark itself, GPL obligations apply to those modifications. Using Wireshark unmodified to analyze your network does not require publishing internal captures or business data.
The WCA certification validates practical skills in capturing, filtering, and analyzing network traffic with Wireshark. It is designed for security, administration, and engineering roles.
Capture & Filters
Capture filters use Berkeley Packet Filter syntax and limit what is written to disk during live capture. Display filters use Wireshark filter syntax and only change what you see in an existing trace. Use capture filters to reduce file size; use display filters to investigate after capture.
Wireshark can decrypt TLS only when you possess appropriate secrets such as pre-master keys from a browser SSLKEYLOGFILE, server private keys for some cipher suites, or configured decryption profiles. It cannot break modern TLS encryption without legitimate key material.
Native format is pcapng. Wireshark also reads pcap and many vendor-specific capture formats. Export subsets via the File menu for sharing filtered results.
Security & Legal
Capturing traffic on networks you own or are explicitly authorized to monitor is generally acceptable for troubleshooting and security. Capturing other parties' communications without permission may violate local law and workplace policy. Read our Trust & Security page for ethical usage guidance.
Official Wireshark installers do not bundle malware, adware, or spyware. Antivirus alerts often stem from Npcap driver behavior required for packet capture. Always verify SHA256 hashes and digital signatures before installing. See Guides: Antivirus.
Security issues should be reported through the project's responsible disclosure process described in project security documentation. Do not publish exploit details before coordinated release of a fix.
Installation
Npcap provides the Windows packet capture driver Wireshark uses to access network adapters. Without it, interfaces may not appear or capture will fail. Install Npcap during Wireshark setup unless you only analyze existing trace files offline.
Need more help?
Browse step-by-step guides or download the latest stable build.