Skip to content

Networking

Reading a packet capture without drowning

26/09/2026 · 2 min read · Tanveer Ahmed

A packet capture is the most complete evidence available and the easiest to waste. Open a large one without a plan and you will scroll for an hour and learn nothing.

Capture narrowly

Filter at capture time, not just at display time. A targeted capture is smaller, faster and more likely to contain the event you care about rather than having rotated past it.

tcpdump -ni eth0 host 10.1.1.5 and port 443 -w /tmp/case.pcap
tcpdump -ni eth0 -s 128 host 10.1.1.5      # headers only

Start with the summary, not the packets

In Wireshark, Statistics before anything else. Protocol Hierarchy tells you what is actually on the wire. Conversations tells you who is talking and how much. Expert Information surfaces retransmissions, resets and malformed frames. Three clicks usually narrows two million frames to the few hundred that matter.

Useful display filters

tcp.analysis.retransmission
tcp.flags.reset == 1
tcp.analysis.zero_window
dns.flags.rcode != 0
http.response.code >= 400

Read the handshake

For any TCP problem, find the SYN. The handshake tells you the round-trip time, the negotiated MSS, whether window scaling and selective acknowledgement were agreed, and how long the server took to respond. Much of the diagnosis is in the first three packets.

Interpret what you find

Retransmissions mean loss somewhere. Zero window means the receiver cannot keep up, which is an application or host problem, not a network one. A reset immediately after the handshake usually means something refused the session deliberately. A long gap between request and response points at the server, not the path.

The habit that matters: decide what you expect to see before you open the file. A capture answers questions. It does not ask them for you.