Wireshark vs tcpdump: catalog facts
Wireshark | tcpdump |
|
Free Free and open source. The foundation is funded by sponsors, training and certification. |
Free Free and open source under the BSD licence. |
|
Windows, macOS, Linux |
Windows, macOS, Linux, Command line |
- Dissectors for hundreds of protocols, so the packet contents are readable rather than hex
- Display filters that cut a huge capture down to one conversation
|
- Available on practically every Unix system, including embedded ones
- Writes standard pcap files that every other tool can read
|
- Capturing on most systems needs elevated privileges or a driver such as Npcap
- The interface assumes you already know roughly what you are looking for
|
- Needs elevated privileges to capture
- Output is dense and takes practice to read
|
|
Downloadable app |
Downloadable app |
|
Open source |
Open source |
|
License: GPL-2.0 |
License: BSD-3-Clause |
|
No account needed |
Not stated if an account is needed |
|
Works offline |
Not stated if it works offline |
Checked September 20, 2026 | Checked September 22, 2026 |
Catalog facts only. Anything “not stated” is unconfirmed. Check full listings for details.
Copy comparison link