tcpdump vs Wireshark: catalog facts
tcpdump | Wireshark |
|
Free Free and open source under the BSD licence. |
Free Free and open source. The foundation is funded by sponsors, training and certification. |
|
Windows, macOS, Linux, Command line |
Windows, macOS, Linux |
- Available on practically every Unix system, including embedded ones
- Writes standard pcap files that every other tool can read
|
- Dissectors for hundreds of protocols, so the packet contents are readable rather than hex
- Display filters that cut a huge capture down to one conversation
|
- Needs elevated privileges to capture
- Output is dense and takes practice to read
|
- Capturing on most systems needs elevated privileges or a driver such as Npcap
- The interface assumes you already know roughly what you are looking for
|
|
Downloadable app |
Downloadable app |
|
Open source |
Open source |
|
License: BSD-3-Clause |
License: GPL-2.0 |
|
Not stated if an account is needed |
No account needed |
|
Not stated if it works offline |
Works offline |
Checked September 22, 2026 | Checked September 20, 2026 |
Catalog facts only. Anything “not stated” is unconfirmed. Check full listings for details.
Copy comparison link