I am new in packet analysis, The team I work with is having a big argument about which tool is better. so I decided to make it an open discussion and see your responses. thank you asked 14 Sep '14, 10:12 Almeida edited 14 Sep '14, 14:11 Guy Harris ♦♦ |
2 Answers:
"Which tools is better" is the same as asking about "PC vs. Mac", "Windows vs. Linux", "iPhone vs. Android", etc. - not really a good question to ask, because it depends on what you need. Both Wireshark and Omnipeek are good tools, both have their strength and weaknesses. The two things where nobody will ever be able to beat Wireshark are
Things were Wireshark can be less optimal to use for are
There are probably more things, but any network analyst worth her/his salt will tell you that they combine different tools to get their results. Usually, Wireshark is the most trusted tool when it comes to decodes. answered 14 Sep '14, 11:41 Jasper ♦♦ |
I think there IS a major difference between Wireshark and OmniPeek especially when it comes to the question of "What is the purpose of performing the capture over WiFi?" Over the last year I asked a similar question on a blog regarding WiFi. After receiving many responses from across the industry (including IT Professionals, developers, education professionals, and hobbyists), there seems to be two different types of thinking when it comes to WiFi capturing:
answered 21 Apr '15, 06:37 Amato_C |
nice thanks a lot.
Another advantage of Wireshark over OmniPeek:
If you're running some flavor of UN*X (Linux, OS X, *BSD, Solaris, AIX, HP-UX, etc.) rather than Windows, and don't have a virtual machine running Windows, and don't have a tool such as Wine that lets you run Windows binaries on your operating system, you can run Wireshark but you can't run OmniPeek. :-)
Another advantage of OmniPeek over Wireshark:
On Windows, OmniPeek can, with popular Wi-Fi adapters, capture in "monitor mode" and see traffic to or from other hosts and get radio information; Wireshark can't, because it uses WinPcap, which (currently) can't capture in monitor mode.