### JOHLEM.net ### --- WIRESHARK # To start capturing packets on a specified interface Capture>"Interfaces ...">[Select interface(s)]>Start # To stop a running capture to analyze the packets Capture>Stop # To apply a filter from selected packets in a current or previous capture session [Right click packet]>"Apply as filter">[Select options] # To start a session that will only capture packets destined for your device Capture>"Options...">[Uncheck "Use promiscuious mode on all interfaces"]>Start # To view all packets of a TCP/UDP/SSL stream [Right click packet]>"Follow stream" # To manage decryption keys to decrypt encrypted streams View>"Wireless Toolbar" then "Wireless Toolbar">"Decryption Keys..."