Wireshark 与 tcpdump 非常相似,但它具有图形化前端,以及更多信息排序和过滤选项。通过将网络接口置于混杂模式,它允许用户查看通过网络(通常是以太网,但正在添加对其他网络的支持)的所有流量。
* Data can be captured "from the wire" from a live network connection or read from a file that recorded already-captured packets.
* Live data can be read from a number of types of network, including Ethernet, IEEE 802.11, PPP, and loopback.
* Captured network data can be browsed via a GUI, or via the terminal (command line) version of the utility, tshark.
* Captured files can be programmatically edited or converted via command-line switches to the "editcap" program.
* Data display can be refined using a display filter.
* Plug-ins can be created for dissecting new protocols.
或者你也可以看看Microsoft 网络监视器(netmon)如果您使用 Windows: