WireShark is the world's foremost network protocol analyzer, and is the de facto standard across many industries and educational institutions.
- Deep inspection of hundreds of protocols, with more being added all the time
- Live capture and offline analysis
- Standard three-pane packet browser
- Multi-platform: Runs on windows,Linux, OS X, Solaris, FreeBSD, NetBSD, and many others
- captured network data can be browsed via a GUI, or Via the TTY-mode Tshark utility
- The most powerful display filters in the industry
- Rich VoIP analysis
- Read/Write many different capture file formats
- Capture files compressed with gzip can be decompressed on the fly Live data can be read from Ethernet, IEEE 802.11, PPP/HDLC, ATM, Bluetooth, USB, Token Ring, Frame Relay, FDDI, and others (depending on your platfrom)
- Decryption support for many protocols, including IPsec, ISAKMP, Kerberos, snmpv3, SSL/TLS WEP, and WPA/WPA2
- Coloring rules can be applied to the packet list for quick, intuitive analysis
- Output can be exported to XML, PostScript , CSV, or plain text.