tcpflow vs Wireshark: catalog facts
tcpflow | Wireshark |
|
Free Free and open source. |
Free Free and open source. The foundation is funded by sponsors, training and certification. |
|
Linux, Command line |
Windows, macOS, Linux |
- Reconstructs full TCP streams into files
- Works on live capture or saved pcap files
|
- Dissectors for hundreds of protocols, so the packet contents are readable rather than hex
- Display filters that cut a huge capture down to one conversation
|
- Command-line only
- Usually built from source
|
- Capturing on most systems needs elevated privileges or a driver such as Npcap
- The interface assumes you already know roughly what you are looking for
|
|
Downloadable app |
Downloadable app |
|
Open source |
Open source |
|
License not stated |
License: GPL-2.0 |
|
No account needed |
No account needed |
|
Works offline |
Works offline |
Checked October 1, 2026 | Checked September 20, 2026 |
Catalog facts only. Anything “not stated” is unconfirmed. Check full listings for details.
Copy comparison link