About Wireshark
Wireshark is a network traffic analyzer, sometimes called a sniffer, that captures packets and lets you inspect them in detail. It runs on Linux, macOS, BSD and other Unix-like systems as well as Windows, and is widely used for troubleshooting networks and studying protocols.
The graphical interface is built with Qt, and packet capture and filtering rely on libpcap and npcap. The distribution also includes TShark, a line-oriented sniffer similar to tcpdump that uses the same dissection, capture file reading and writing, and packet filtering code, and editcap, which converts capture files and can remove packets. Official installers exist for Windows and macOS, and packages are available for many Linux and BSD distributions.
The code is written in C and licensed under GPL-2.0. This GitHub repository is a read-only mirror of the project's GitLab repository, where changes and pull requests are submitted. The official home of the project is wireshark.org, where the latest releases are published.
Key features
- Live packet capture and inspection
- Qt graphical interface
- TShark command-line analyzer
- editcap for converting capture files
- Display and capture filtering
- Runs on Windows, macOS, Linux and BSD
Good fit for
- →Troubleshooting network problems
- →Analyzing protocol traffic for security work
- Built with
- C
- Tags
- packet-analyzer
- network
- protocol-analysis
- tshark
- security
- pcap
- troubleshooting
Wireshark: questions and answers
- What is Wireshark used for?
- Wireshark is a network protocol analyzer that captures and inspects packets, with a graphical interface and the command-line TShark for scripting. It is a good fit for troubleshooting network problems and analyzing protocol traffic for security work.
- Is Wireshark open source?
- Yes. Wireshark is open source under the GPL-2.0 licence. Its source code is on GitHub at wireshark/wireshark and is written mainly in C.
- Is Wireshark free?
- Yes. Wireshark is open source, so the software itself is free to use.
- What are some alternatives to Wireshark?
- Similar open-source tools in the Networking & VPN category include Pi-hole, AdGuard Home and Cilium. SaaS products in the same category include Akamai, Cloudflare and CyberGhost.
- Is Wireshark actively maintained?
- Yes. The most recent commit to Wireshark was on 2 October 2026. The project has 9.9k stars on GitHub.
Open-source alternatives to Wireshark
See all
Pi-hole
Networking & VPN
A black hole for Internet advertisements
OSSvs Cisco Umbrella★ 61k
AdGuard Home
Networking & VPN
Network-wide ads & trackers blocking DNS server
GPL-3.0vs Cisco Umbrella★ 37k
Cilium
Networking & VPN
eBPF-based Networking, Security, and Observability
Apache-2.0vs Illumio★ 26k
Nebula
Networking & VPN
A scalable overlay networking tool with a focus on performance, simplicity and security
MITvs Tailscale★ 18k
LibreSpeed
Networking & VPN
Self-hosted Speed Test for HTML5 and more. Easy setup, examples, configurable, mobile frie
LGPL-3.0vs Speedtest by Ookla★ 15k
OpenVPN
Networking & VPN
OpenVPN is an open source VPN daemon
OSSvs NordLayer★ 15k
SaaS alternatives to Wireshark
See all
Akamai
Networking & VPN
CDN, security and edge compute platform for enterprise web delivery
SaaS
Cloudflare
Networking & VPN
CDN, DNS, DDoS protection and edge computing platform
SaaS
CyberGhost
Networking & VPN
Consumer VPN service with streaming-optimized servers and a no-logs policy
SaaS
ExpressVPN
Networking & VPN
Consumer VPN service with apps for desktop, mobile, routers and browsers
SaaS
hide.me
Networking & VPN
VPN service with a no-logs policy and a free plan
SaaS
Hotspot Shield
Networking & VPN
Consumer VPN with its own transport protocol and a limited free version
SaaS

