Wireshark¶
What Wireshark does¶
Guided SUSA tool journey
Wireshark supports network forensics. In this guide, you will use it to filter a supplied PCAP, follow one conversation, and export relevant evidence safely. The procedure and screenshots provide the practical reference; the surrounding context explains what to record and how to judge the result.
Tool guide at a glance¶
Filter a supplied PCAP, follow one conversation, and export relevant evidence safely.
A supplied PCAP or network-session dataset with capture-point and timing notes.
A reconstructed communication with filters, endpoints, protocol context, and capture limitations.
Evidence and safety
Use supplied captures or traffic from an authorised lab. Do not interact with suspicious external infrastructure. Record the input identifier, tool version, relevant commands or settings, time and time zone, output location, and any errors or limitations as you work.
Choose your journey¶
01Understand the evidenceLearn the network forensics concepts and limitations.Complete when you can explain what the evidence can and cannot show.Beginner · No tool required · 15–25 min 02Follow the Wireshark guideWork through the commands, screenshots, and instructional sequence below.Complete when the documented workflow produces its expected output.Guided · SUSA workstation · Time varies 03Interactive labPractise the tool workflow in a safe browser simulation.Complete when the guided result is supported by the case evidence.Beginner · Browser only · 10–20 min 04Full LabInvestigate an authorised training scenario with fewer prompts and preserve a reviewable result.Complete when another analyst can reproduce and verify the outcome.Intermediate · Isolated lab · 45–90 min
How the labs complement this guide
The Interactive Lab is a safe browser simulation for practising the workflow and validation logic. The Full Lab is an independent exercise for an isolated, authorised environment. Confirm the installed tool version and expected output before relying on either exercise in a real case.
Accessing Wireshark in SUSA¶
Wireshark is a network protocol analyser which presents captured packet data in as much detail as possible.
Download Wireshark for Windows.
Move the downloaded executable to C:\Tools\Wireshark and double-click it to begin install. When prompted by the User Account Control, select Yes.
Click Next.
Click Noted for License Agreement
Click Next.
Check the box for Wireshark Desktop Icon and click Next.
Leave the Destination Folder as is and click Next.
Leave Install Npcap checked and click Next.
Leave Install USBPcap unchecked and click Install.
Once the install is complete, select Reboot now and click Finish.
If prompted for License Agreement for Npcap, click I Agree.
Leave all the options unchecked and click Install.
Once Npcap install is complete, click Next, then Finish.
Click Next on the Wireshark Setup Wizard.
Select Reboot now and click Finish.
Move the Wireshark desktop shortcut to C:\Tools\Wireshark.
Open Wireshark and confirm that the application starts without an error.
Double-click Ethernet0 to test packet capture. Wait until network packets are captured then click Stop.
Malware Traffic Analysis using Wireshark¶
Review Understanding Network Forensics before conducting malware traffic analysis using Wireshark.



















