Wireshark for Beginners provides a practical foundation in packet capture and traffic analysis. The course pairs 10 guided labs with 10 short challenges, so each major topic is first explained through a walkthrough and then reinforced with a focused task and a concrete file or configuration result.
You will progress from installation and capture permissions to the Wireshark interface, live capture, display and capture filters, coloring rules, TCP streams, packet export, IPv6, and Tshark. The exercises combine traffic you generate yourself with supplied PCAP and PCAPNG files, helping you practice both collection and repeatable offline analysis.
What You Will Learn
After completing this course, you will be able to:
- Install Wireshark on Ubuntu and configure
dumpcapgroup permissions and Linux capabilities for non-root packet capture - Navigate the packet list, details, and bytes panes and customize layouts, columns, profiles, and traffic-coloring rules
- Select an appropriate interface, capture live traffic, inspect protocol layers, and save or reopen PCAPNG files
- Build display filters for protocols, addresses, ports, flags, fields, and packet content to isolate HTTPS, DNS, HTTP, clear-text credentials, and other traffic of interest
- Apply BPF capture filters before collection and explain how their purpose and syntax differ from Wireshark display filters
- Reconstruct and save TCP streams, isolate a stream by index, and use protocol hierarchy, conversation, endpoint, and I/O statistics for context
- Export displayed or selected packets, packet dissections, and raw bytes in PCAP, CSV, text-oriented, and binary forms for further review
- Capture and inspect IPv6 and ICMPv6 traffic, examine Next Header values, and use Tshark filters, field extraction, statistics, format conversion, and shell pipelines
Who This Course Is For
This course is for networking students, help-desk and system administration learners, junior security analysts, and cybersecurity beginners who want a structured introduction to packet-level investigation. It suits learners who want both graphical practice and an initial command-line workflow without assuming previous Wireshark experience.
Prerequisites: Basic Linux terminal use and an introductory understanding of IP addresses, TCP and UDP ports, DNS, HTTP, and HTTPS are recommended. The course introduces packet layout and filter syntax from the beginning.
Learning environment: All units use a privileged Ubuntu graphical LabEx environment with Wireshark, a terminal, local traffic-generation scripts, and supplied capture files where specified. Installation uses Ubuntu package repositories, while several live-capture examples contact public hosts such as Google, LabEx, or example.com. The final guided lab also installs and uses Tshark.
Frequently Asked Questions
Does every exercise require live internet traffic?
No. Several challenges and guided steps use supplied capture files or local traffic-generation scripts. Other steps install packages or generate traffic against public hosts, and the course content explicitly notes that some live internet exercises may be unavailable to free LabEx users.
Will I learn to decrypt HTTPS traffic?
No. You will isolate port 443 traffic, recognize TLS-related communication, and follow encrypted TCP streams, but the course does not configure session keys or decrypt HTTPS application content.
Does the course include Tshark or only the Wireshark GUI?
Most units use the graphical interface. The final guided lab and challenge introduce Tshark for capture-file reading, display filtering, field extraction, statistics, PCAP conversion, and pipelines with commands such as sort and uniq.
What is the difference between capture filters and display filters in this course?
Capture filters use BPF syntax to decide which packets are recorded, reducing the dataset at collection time. Display filters use Wireshark field syntax after capture and can be changed repeatedly without removing packets from the saved data.




