This is our old Q&A Site. Please post any new questions and answers at

Looking on how to extract the Information column that is displayed in wireshark from a completed capture using Tshark and dumping it into a text file. I know it can be done with Wireshark manually but I need to do it from command-line so it can be used in a script. I am familiar with some commands of Tshark but can't figure the correct switch to get the "Information Column".

tshark - r <input> -T fields (questionable part) > output.txt

Use case: After outputting the information column to a text file will use Powershell to extract any names of executables which have an executbale extension and have been downloaded i.e. .bat, .com, .scr, .exe, etc. This will be for a work network, obvious there should be many .exe's for various softwares updating periodically but any of the others will hopefully alert us to nefarious activities.

asked 26 Dec '14, 21:32

zer0day's gravatar image

accept rate: 60%

Funny, it always seems to happen, soon as I ask a question I then find my answer excuse my process. The command below does what I was looking for.

tshark -V -r path\capture.cap > path\output.txt
permanent link

answered 26 Dec '14, 22:05

zer0day's gravatar image

accept rate: 60%

If you are using windows´╝î pls try

tshark -T fields _ws.col.Info

_ws.col I think that mean wireshark column and .Info must be samed with colume name

permanent link

answered 29 Jan '15, 06:39

Hu%20Paul's gravatar image

Hu Paul
accept rate: 0%

Was helpful, thanks for sharing

(31 Jan '15, 21:57) zer0day

@Hu Paul Thanks a lot for sharing this (y)

(25 Mar '16, 06:14) rabeeljaved
Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 26 Dec '14, 21:32

question was seen: 7,971 times

last updated: 25 Mar '16, 06:14

p​o​w​e​r​e​d by O​S​Q​A