H3AD-REF / CHEATSHEETS / WIRESHARK DISPLAY FILTERS

Wireshark Filters.
The Ones You Actually Type.

A static reference for Wireshark display filter syntax: the operators that chain conditions together, filters built for four scenarios you'll actually triage, and the fields worth memorizing after the third lookup. No capture engine here, just the syntax and when to reach for it. For what those header fields actually look like byte by byte, see the Packet Structure Reference.

Filter Syntax Basics

Every filter is a comparison, a chain of comparisons, or both. Get these two families right and the rest is just field names.

SYNTAX

Comparison Operators

Compare a field against a value or another field
  • == — exact match, most filters start here
  • != — excludes a value, but watch multi-valued fields
  • contains — substring match anywhere in the field
  • matches — regex match against a field's value
ip.addr != 10.0.0.5 looks like it excludes a host, but ip.addr holds two values per packet, source and destination. A packet from 10.0.0.5 to anywhere still has that address on one side, so the whole packet gets excluded instead of just one direction. Use !(ip.addr == 10.0.0.5) when the intent is genuinely "neither side is this host."
SYNTAX

Logical Operators

Chain comparisons into one filter expression
  • && — AND, both sides must hold
  • || — OR, either side is enough
  • ! — NOT, negates whatever follows it
tcp.port == 80 && ip.src == 10.0.0.5 narrows to one host's traffic on one port. Wrap OR'd terms in parentheses before negating them, since !a || b and !(a || b) don't evaluate the same way.

Filters By Scenario

The filter gets you to the packets. Confirming the finding is still on you.

SCENARIO

ARP Spoofing

Two ways to catch a poisoned cache
  • arp.duplicate-address-detected — Wireshark's own flag for an IP claimed by more than one MAC address in the capture
  • eth.dst != arp.src.hw_mac — catches an ARP reply whose claimed hardware address doesn't match the frame's real source MAC
Run both, not just one, and cross-check the MAC-to-IP pairs against what the network is supposed to have. A virtualized host or a failover pair can trip either filter without anyone actually spoofing anything.
SCENARIO

DNS Tunneling

Volume and shape, not one packet
  • dns.qry.name.len > 50 — flags query names long enough to be carrying encoded data instead of a real hostname
  • repeated TXT queries to the same parent domain — filter dns.qry.type == 16 and check volume in Statistics > DNS, not a single lookup
  • high-entropy subdomain labels, long runs of what looks like random characters — no filter catches this reliably, treat it as a manual-review signal
None of these three convict a domain by themselves. CDNs and mail infrastructure produce long queries and odd-looking subdomains often enough that it's the combination, not any single hit, that earns a closer look.
SCENARIO

Beaconing

Isolate the attempts, then check the clock
  • tcp.flags.syn==1 && tcp.flags.ack==0 — isolates outbound connection attempts, not established sessions
  • Statistics > Conversations, sorted by duration or packet count, to see which host pairs recur
The SYN filter narrows the capture to attempts; the interval between them tells you whether it's a person clicking a link or a process on a timer. Fixed gaps of 60, 300, or 3600 seconds with near-identical packet sizes are the pattern to chase, not the filter itself.
SCENARIO

Credentials In Cleartext

Three protocols, one filter each
  • http contains "password" — catches the literal string in headers or POST bodies; it's case-sensitive, so run a second pass for Password or PASSWORD
  • ftp.request.command == "PASS" — the FTP command that carries the password argument in plaintext
  • telnet contains "password" — same idea as HTTP, applied to the Telnet stream
All three exist because none of these protocols were built to hide anything from a capture. Getting the hit is the easy part; confirming the session actually authenticated is the part worth writing up.

Field Quick-Reference

Seven fields that cover most first-pass triage. Everything else is a variation on one of these.

Fields Worth Memorizing

ip.addr
// matches if source OR destination IP equals the value, either direction

ip.src  /  ip.dst
// one-directional: src for outbound only, dst for inbound only

tcp.port
// matches if source OR destination TCP port equals the value, either direction

tcp.flags.syn
// isolates the SYN flag, the first packet of a TCP three-way handshake

http.request.method
// filters to one HTTP verb, e.g. == "POST" to isolate uploads and logins

dns.qry.name
// matches a DNS query name; combine with .len for length-based filters

tls.handshake.type
// type 1 is Client Hello, type 2 is Server Hello, both useful for SNI inspection