2026 Wireshark Display Filter vs tcpdump BPF Capture Syntax Table
2026 Verified ReferenceWireshark uses two distinct filter engines: Berkeley Packet Filters (BPF, shared with `tcpdump`) filter raw packets at the kernel NIC driver before writing to disk (`host 10.0.0.5 and tcp port 443`), whereas Wireshark Display Filters parse deep Layer-7 protocol fields (`http.request.method == "POST"` or `tls.handshake.type == 1`) during post-capture analysis.
tcpdump -ni any 'tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn' -w syn_scan.pcap| Packet Analysis Goal | Wireshark Display Filter | tcpdump BPF Capture Filter | SOC / Network Triage Purpose |
|---|---|---|---|
| Isolate Host IP & Port | ip.addr == 10.10.14.5 && tcp.port == 443 | host 10.10.14.5 and tcp port 443 | Inspect bidirectional flow for a single endpoint |
| Detect TCP SYN Port Scans | tcp.flags.syn == 1 && tcp.flags.ack == 0 | tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn | Spots Nmap -sS sweeps & SYN flood DDoS bursts |
| Hunt HTTP POST & Auth Flows | http.request.method == "POST" || http.response.code >= 400 | tcp port 80 and (((ip[2:2] - ((ip[0]&0xf)<<2)) - ((tcp[12]&0xf0)>>2)) != 0) | Extracts form logins, API calls & 4xx/5xx errors |
| Inspect TLS ClientHello & SNI | tls.handshake.type == 1 && tls.handshake.extensions_server_name | tcp port 443 and (tcp[((tcp[12]&0xf0)>>2)] = 0x16) | Identifies destination domain names inside HTTPS |
| Audit DNS Queries & AXFR | dns.flags.response == 0 || dns.qry.type == 252 | port 53 | Detects C2 DNS tunneling & zone transfer attempts |
| Exclude Your Own SSH Session | !(tcp.port == 22 && ip.addr == 192.168.1.50) | not (tcp port 22 and host 192.168.1.50) | Prevents feedback loop when running remote tcpdump |
