Wireshark with Always-on Packet Capture

Wireshark is a widely-used, open-source network protocol analyzer that shows you what’s happening on your network at a packet level. It’s the de facto standard across commercial, non-profit enterprises, government agencies, and educational institutions for forensic packet analysis.

Wireshark is available for multiple platforms including Windows, Linux, MacOS, FreeBSD and many others and provides multiple built-in protocol decoders and decryption support for many protocols, powerful, user-customizable display filters and rules, and the ability to import and export packet data in multiple file-formats including pcap, pcap-NG, Endace's own Extensible Record Format (ERF) and many others.

Fast search and data-mining with EndaceVision and Wireshark

Why combine Wireshark with the always-on, full packet capture of EndaceProbes?

Capture every threat, breach and outage

Recall every network activity with perfect clarity. Always on packet capture means you always have the data you need.

Visibility across your entire hybrid network

Record weeks to months of traffic from across your distributed, on-premise, public and private cloud network.

Faster investigation and response

Rapid, centralized search and data-mining puts conclusive forensic evidence at your fingertips in seconds not hours.

Powerful forensics

Quickly and accurately reconstruct events, analyze pcap data and reassemble files with InvestigationManager.

Enterprise-class scalability

Your entire estate of EndaceProbes, physical and cloud, managed centrally, with network-wide investigations from a single pane-of-glass.

Wireshark On-board

A full version of Wireshark is hosted on every EndaceProbe and in InvestigationManager too. This lets analysts quickly view decoded packet data directly from EndaceVision without having to download large pcap files.