# Wireshark on Linux, macOS and Windows: packet capture, TShark and the dumpcap privilege split

> Wireshark is a Qt-based network traffic analyzer that ships TShark and editcap alongside it. The capture privilege is isolated in dumpcap, and that design decision shapes how you install and run it.

**wireshark/wireshark** — Read-only mirror of Wireshark's Git repository at https://gitlab.com/wireshark/wireshark. You're welcome to submit pull requests there.

- Repository: https://github.com/wireshark/wireshark
- Website: https://www.wireshark.org
- Stars: 9,944 · Forks: 2,220
- Language: C
- License: GPL-2.0
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/wireshark-wireshark

## What Wireshark is for, and who ends up using it

The README calls Wireshark a network traffic analyzer, or sniffer, for Linux, macOS, BSD and other Unix-like systems and for Windows. It is built on Qt for the interface and on libpcap and npcap for capture and filtering. That combination is the whole product: a graphical dissector over a capture library, plus command-line tools that reuse the same dissection code.

The distribution is not just the GUI. TShark is described as a line-oriented sniffer, similar to snoop or tcpdump, that shares dissection, capture-file reading and writing, and packet filtering with Wireshark. editcap reads capture files and writes packets out again, possibly in a different format and possibly with some packets removed. So the audience splits in two. One group opens a capture in the GUI and reads it. The other never opens the GUI at all and drives TShark or editcap from a shell.

If you are deciding whether to adopt it, the useful question is which of those two you are. The GUI is the part people talk about. The command-line tools are the part that fits into a pipeline.

## dumpcap holds the privilege so the rest does not have to

Capturing packets needs elevated access. The README is explicit about how Wireshark handles that: you make the dumpcap program set-UID to root, or you have access to the appropriate entry under /dev on systems that work that way, which it says typically covers BSD-derived systems and systems such as Solaris and HP-UX that support DLPI.

It then warns against the obvious shortcut. Making the Wireshark and TShark executables setuid root, or running them as root, is described as tempting but wrong. The reason given is that the capture process has been isolated in dumpcap, a simple program that is less likely to contain security holes and is therefore safer to run as root.

That is the architecture in one paragraph. The dissectors, the protocol parsers, the file readers and the GUI all run without capture privilege. Only dumpcap sits on the privileged side. It is a deliberate trade-off: you gain a smaller privileged surface, and you pay for it with an install step that is easy to get wrong, because a set-UID binary has to be placed and permissioned correctly before capture works at all.

## Installing Wireshark and taking a first capture with TShark

The README states that official installation packages are available for Microsoft Windows and macOS, and that Wireshark is available as either a standard or an add-on package for many distributions including Debian, Ubuntu, Fedora, CentOS, RHEL, Arch, Gentoo, openSUSE, FreeBSD, DragonFly BSD, NetBSD and OpenBSD. It also names third-party packaging systems such as pkgsrc, OpenCSW, Homebrew and MacPorts. The latest distribution is at the download subdirectory of wireshark.org. On Debian and Ubuntu the package name is the project name:

```bash
sudo apt install wireshark
```

Building from source is a different path and needs more than a compiler. The README says Python 3 is needed to build Wireshark, AsciiDoctor is required to build the documentation including the man pages, and Perl and flex are required to generate some of the source code. It specifies GNU flex, noting that vanilla lex will not work. Full instructions live in the INSTALL file and the Developer's Guide, with OS-specific notes in the README._OS_ files.

Once installed, the first real use is a capture to a file. The README gives this example for saving a router trace through a shell session:

```bash
$ script tracefile.out
Script started on <date/time>
$ telnet router
$ exit
Script done on <date/time>
```

That pattern exists because some devices, the Lucent/Ascend, Toshiba and CoSine routers the README discusses, do their tracing internally and cannot write the trace to a file themselves. You capture the terminal output instead. For ordinary traffic you would point the capture tool at an interface, and the README directs you to the man page for each command-line option and interface feature rather than listing them.

Two settings are worth knowing before you read anything. Name resolution is on by default for IPv4 and IPv6, and the -n option turns off all of it, including MAC addresses and TCP, UDP and SMTP port numbers. The -N mt option turns off resolution for network-layer addresses only. The same switches exist as options under Name resolution in the Preferences dialog, reachable from the Preferences item in the Edit menu.

## Compressed captures and the formats Wireshark will not open for you

Wireshark reads compressed versions of supported capture files if the matching compression library was present at compile time. The README lists GZIP, LZ4 and ZSTD. It adds a detail that matters for interactive work: GZIP and LZ4, when LZ4 uses independent blocks, which the README says is the default, support fast random seeking, which gives better GUI performance on large files.

Each format can be turned off at build time with a cmake option:

```bash
cmake -DENABLE_ZLIB=OFF
cmake -DENABLE_LZ4=OFF
cmake -DENABLE_ZSTD=OFF
```

So a distribution build may not have all three. If a compressed capture fails to open, the build is the first thing to check, not the file.

The format list is the other gap. The README says Wireshark can read packets from a number of different file types and then points to the Wireshark man page or the Wireshark User's Guide for the list. It does not enumerate them, so you cannot confirm support for a given format from the README alone. The exotic inputs it does describe are narrow: AIX iptrace, whose documentation the README calls sparse, plus debug trace output from Lucent/Ascend MAX and Pipeline products via the wandsession, wandisplay, wannext and wdd commands, Toshiba Compact Router TR-600 and TR-650 dump output started with snoop dump, and CoSine L2 debug output. Those are read from files, not live.

## Where Wireshark is the wrong tool

The privilege model is the first limitation. If you cannot make dumpcap set-UID root and your system does not give you a usable /dev entry, capture does not work, and the README's own advice rules out the workaround of running the GUI or TShark as root. On a managed machine where you cannot change file permissions, that is a hard stop.

The second is scope. Nothing in the README describes continuous monitoring, alerting or retention. Wireshark reads packets and files. If what you want is a system that watches a link indefinitely and tells you when something changes, this is not that, and treating it as that means building the surrounding machinery yourself.

The third is platform drift. The README states that in some cases the current version might not support your operating system, giving Windows XP as an example, supported only by Wireshark 1.10 and earlier. It also notes that for Solaris and HP-UX the standard package might simply be old. If you are on an older or unusual Unix, check the package version before assuming the current release is available to you.

The fourth is the AIX iptrace path specifically. The README says the iptrace command starts a daemon you must kill to stop the trace, and that sending a HUP signal appears to cause a graceful shutdown with a complete packet written to the file. If a partial packet is saved at the end, Wireshark complains when reading the file, though the other packets remain readable. That is a documented rough edge, not a polished import.

## tcpdump and TShark: same capture library, different dissection

The README compares TShark to Sun's snoop and to tcpdump, which is the honest comparison to make. All three sit on a capture library, and Wireshark uses libpcap and npcap. The difference is what happens after the packet arrives.

tcpdump prints a compact, largely fixed representation of each packet's headers. TShark runs the same dissection engine as the Wireshark GUI, so protocol decoding, display filters and the supported file formats are the same as what you see in the graphical tool. That is why the README can describe TShark as sharing dissection, capture-file reading and writing, and packet filtering with Wireshark.

If your need is a quick header dump on a server with nothing installed, tcpdump is the smaller dependency. If your need is to write a capture to a file and then dissect it as a specific protocol, or to reuse the same filter syntax you use in the GUI, TShark is the closer fit. The cost is a larger install and the dumpcap permission step, which tcpdump handles differently.

## Maintenance, licensing and the mirror caveat

The repository is not archived, and the last push was on 2026-09-21. The description states it is a read-only mirror of Wireshark's Git repository at gitlab.com, and that pull requests are welcome there. That matters if you intend to contribute: changes go to GitLab, not to the mirror, so a patch opened against the mirror is not the path the description points at.

On upgrade cost, the README is thin. It documents build-time switches such as the compression options and the toolchain requirements, and it points to INSTALL and the Developer's Guide, but it does not document a rollback procedure or a supported-version policy. If you build from source, treat the toolchain as a recurring cost: Python 3, AsciiDoctor, Perl and GNU flex have to be present, and the README says vanilla lex will not do. Distribution packages move that cost to the packager.

The license is GPL-2.0. That is a copyleft license, and it affects redistribution rather than private use. If you ship Wireshark inside a product, or link against its code, the terms follow the binary. This is a description of the license identifier, not legal advice; read COPYING and get your own counsel for a redistribution question.

## Conclusion

Adopt Wireshark when you need to read packets by hand or script a capture pipeline with TShark, and you accept the GPL-2.0 terms that come with redistributing it. Do not adopt it as a long-running passive monitor or an intrusion detection system: the README describes an analyzer, and dumpcap is the only piece designed to hold capture privilege. Before relying on it, verify that dumpcap is set-UID to root or that your user has the right /dev entry, then confirm the file format you need is in the supported list, since the README points to the man page and User's Guide for that list rather than enumerating it.

## FAQ

### What is Wireshark used for?

It is a network traffic analyzer, or sniffer, that captures packets and dissects them. The same distribution includes TShark, a line-oriented sniffer that shares the dissection and filtering code, and editcap, which rewrites capture files.

### Is Wireshark an IP sniffer?

It captures and decodes network traffic, including IPv4 and IPv6, and by default it attempts reverse name resolution on those packets. The -n option turns off all name resolution, and -N mt turns off resolution for network-layer addresses.

### How do I install Wireshark on Ubuntu?

It is available as a standard or add-on package for Ubuntu and Debian, so the distribution package manager is the normal route. The README also points to the INSTALL file and the Developer's Guide for building from source, which needs Python 3, AsciiDoctor, Perl and GNU flex.

### How do I capture network traffic with Wireshark?

Capture requires elevated access, which the README handles by making dumpcap set-UID to root or by granting access to the appropriate /dev entry. It advises against making the Wireshark or TShark executables setuid root, or running them as root, because dumpcap isolates the privileged capture process.

### How do I use Wireshark on Linux?

Wireshark runs on Linux, where it is available as a standard or add-on package for distributions including Debian, Ubuntu, Fedora, CentOS, RHEL, Arch, Gentoo and openSUSE. The README points to README.linux and the INSTALL file for OS-specific build instructions.

## Sources

- [Issues](https://github.com/wireshark/wireshark/issues)
- [License: GPL-2.0](https://github.com/wireshark/wireshark/blob/master/LICENSE)
- [Project website](https://www.wireshark.org)
- [README](https://github.com/wireshark/wireshark/blob/master/README.md)
- [wireshark/wireshark on GitHub](https://github.com/wireshark/wireshark)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/wireshark-wireshark
