Everything on your network is having a conversation: your laptop and the router, the router and the server, the server and a dozen others. Most people never see any of it. Wireshark lets you read every word — and once you can, you never look at a network the same way again. This Cover6 Community session is a hands-on walkthrough of the most widely used protocol analyzer in the industry.
Use this post as your read-ahead, then come back to it for the filters.
What Wireshark actually does
Wireshark captures the packets crossing a network interface and shows you each one, decoded. Instead of “the page loaded,” you see the DNS lookup that found the server, the TCP handshake that opened the connection, and the bytes that moved. It’s the closest thing to seeing the network with your own eyes — which is why it’s a core tool for SOC analysts, network engineers, and pentesters alike.
Capture on a network you own or are authorized to monitor. Watching traffic that isn’t yours is a different thing entirely.
Capture, then filter
A live capture fills up fast — thousands of packets in seconds. The skill isn’t capturing; it’s filtering down to the conversation you care about. Wireshark’s display filters are how you do that. A few you’ll use constantly:
ip.addr == 10.0.0.5
Show only packets to or from one host.
tcp.port == 443
Narrow to a service — here, HTTPS.
http
Show only HTTP traffic. Swap in dns, arp, icmp, or tls to isolate a protocol.
ip.addr == 10.0.0.5 && tcp.port == 80
Combine them with && to zero in. Filter first, read second — that’s the whole workflow.
Follow the stream
A single packet is a word; a stream is the whole sentence. Right-click a packet and “Follow TCP Stream,” and Wireshark reassembles the entire back-and-forth of that connection into one readable view — the request, the response, everything in order. For an unencrypted protocol, you can read the exchange like a transcript. It’s the single most useful move for understanding what a connection was actually doing.
In the session we capture a live ping and watch the ICMP request-and-reply, then follow a full TCP stream end to end — the handshake, the data, the teardown. Seeing it once makes the abstract concrete.
Why this is a defender’s superpower
When an alert fires and you need to know what really happened, the packets don’t lie. Wireshark (and its command-line sibling, tshark) is how a SOC analyst confirms whether that “suspicious connection” was a real exfiltration or a noisy backup job. Network forensics — reconstructing an incident from a packet capture — is built on exactly these skills: filter to the host, follow the stream, read the conversation.
Practice it in a live lab, free
The way to get comfortable with packet analysis is to capture real traffic and pick it apart. First Watch gives you a live Splunk lab and your first SOC shift, free — where network and log data come together and you learn to read what’s moving across the wire the way an analyst does.
👉 Start here, free: https://www.cover6solutions.com/product/cover6-first-watch-free-access/
Building the offensive side instead? First Shell gives you an authorized target to attack, free, where watching your own traffic in Wireshark teaches you how loud your moves are: https://www.cover6solutions.com/product/cover6-first-shell-free-access/
Where this path leads
Packet analysis is foundational on both the SOC Analyst and Penetration Tester paths on Chrysalus. Build your free profile and add a capture analysis as a project.
- Read the SOC Analyst Roadmap 2026 and the Pentester Roadmap 2026.
- Not sure which lane? Take the free career path assessment.
- Use the Cover6 Field Manual as a free reference, and browse every Cover6 course.
- Join The 6, our free newsletter, to catch the next session.
Watch the replay
We ran this live in the Cover6 Community — live capture, display filters, a live ping, and a full TCP stream, start to finish. Planning to attend a future meetup? Use this post as your read-ahead, and catch the replay above.
