H3AD-REF / CHEATSHEETS / WIRESHARK DISPLAY FILTERS
Wireshark Filters.
The Ones You Actually Type.
A static reference for Wireshark display filter syntax: the operators that chain conditions together, filters built for four scenarios you'll actually triage, and the fields worth memorizing after the third lookup. No capture engine here, just the syntax and when to reach for it. For what those header fields actually look like byte by byte, see the Packet Structure Reference.
Filter Syntax Basics
Every filter is a comparison, a chain of comparisons, or both. Get these two families right and the rest is just field names.
SYNTAX
Comparison Operators
Compare a field against a value or another field
==— exact match, most filters start here!=— excludes a value, but watch multi-valued fieldscontains— substring match anywhere in the fieldmatches— regex match against a field's value
ip.addr != 10.0.0.5 looks like it excludes a host, but ip.addr holds two values per packet, source and destination. A packet from 10.0.0.5 to anywhere still has that address on one side, so the whole packet gets excluded instead of just one direction. Use !(ip.addr == 10.0.0.5) when the intent is genuinely "neither side is this host."
SYNTAX
Logical Operators
Chain comparisons into one filter expression
&&— AND, both sides must hold||— OR, either side is enough!— NOT, negates whatever follows it
tcp.port == 80 && ip.src == 10.0.0.5 narrows to one host's traffic on one port. Wrap OR'd terms in parentheses before negating them, since !a || b and !(a || b) don't evaluate the same way.
Filters By Scenario
The filter gets you to the packets. Confirming the finding is still on you.
SCENARIO
ARP Spoofing
Two ways to catch a poisoned cache
arp.duplicate-address-detected— Wireshark's own flag for an IP claimed by more than one MAC address in the captureeth.dst != arp.src.hw_mac— catches an ARP reply whose claimed hardware address doesn't match the frame's real source MAC
SCENARIO
DNS Tunneling
Volume and shape, not one packet
dns.qry.name.len > 50— flags query names long enough to be carrying encoded data instead of a real hostname- repeated TXT queries to the same parent domain — filter
dns.qry.type == 16and check volume in Statistics > DNS, not a single lookup - high-entropy subdomain labels, long runs of what looks like random characters — no filter catches this reliably, treat it as a manual-review signal
SCENARIO
Beaconing
Isolate the attempts, then check the clock
tcp.flags.syn==1 && tcp.flags.ack==0— isolates outbound connection attempts, not established sessions- Statistics > Conversations, sorted by duration or packet count, to see which host pairs recur
SCENARIO
Credentials In Cleartext
Three protocols, one filter each
http contains "password"— catches the literal string in headers or POST bodies; it's case-sensitive, so run a second pass forPasswordorPASSWORDftp.request.command == "PASS"— the FTP command that carries the password argument in plaintexttelnet contains "password"— same idea as HTTP, applied to the Telnet stream
Field Quick-Reference
Seven fields that cover most first-pass triage. Everything else is a variation on one of these.
Fields Worth Memorizing
ip.addr // matches if source OR destination IP equals the value, either direction ip.src / ip.dst // one-directional: src for outbound only, dst for inbound only tcp.port // matches if source OR destination TCP port equals the value, either direction tcp.flags.syn // isolates the SYN flag, the first packet of a TCP three-way handshake http.request.method // filters to one HTTP verb, e.g. == "POST" to isolate uploads and logins dns.qry.name // matches a DNS query name; combine with .len for length-based filters tls.handshake.type // type 1 is Client Hello, type 2 is Server Hello, both useful for SNI inspection