Wireshark Display Filter & tcpdump BPF Capture Syntax Builder (2026)

Construct exact Wireshark display filters and matching tcpdump Berkeley Packet Filter (BPF) CLI commands for SYN scans, ARP spoofing, TLS handshakes, DNS tunneling, and HTTP anomalies.

Wireshark Display Filter & tcpdump BPF Syntax Builder — Interactive Console
Runs locally in your browser • Instant output
Wireshark Display Filter
tcp && ip.src == 10.10.14.22 && ip.dst == 192.168.1.0/24 && tcp.port == 443 && tcp.flags.syn == 1 && frame contains "password" && !(tcp.port == 22 || tcp.port == 3389)
tcpdump BPF CLI Command
$ sudo tcpdump -i any -nn -v -s0 'tcp and src host 10.10.14.22 and dst net 192.168.1.0/24 and port 443 and (tcp[tcpflags] & (tcp-syn) != 0) and not port 22 and not port 3389' -A | grep -i --color "password"
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Wireshark Display Filter & tcpdump BPF Syntax Builder](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/wireshark-tcpdump-filter-builder/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/wireshark-tcpdump-filter-builder/">Wireshark Display Filter & tcpdump BPF Syntax Builder — ZerosUniverse</a>

2026 Wireshark Display Filter vs tcpdump BPF Capture Syntax Table

2026 Verified Reference
Quick Answer & 2026 Technical Summary (wireshark filter generator)Updated 2026 Standard

Wireshark uses two distinct filter engines: Berkeley Packet Filters (BPF, shared with `tcpdump`) filter raw packets at the kernel NIC driver before writing to disk (`host 10.0.0.5 and tcp port 443`), whereas Wireshark Display Filters parse deep Layer-7 protocol fields (`http.request.method == "POST"` or `tls.handshake.type == 1`) during post-capture analysis.

tcpdump -ni any 'tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn' -w syn_scan.pcap
Zero-Overhead Capture Flag: tcpdump -ni eth0 -s 0 -w capture.pcap
SYN-Only BPF Expression: tcp[13] == 2 (or tcp[tcpflags] == tcp-syn)
TLS SNI Hostname Filter: tls.handshake.extensions_server_name contains "domain"
Packet Analysis GoalWireshark Display Filtertcpdump BPF Capture FilterSOC / Network Triage Purpose
Isolate Host IP & Portip.addr == 10.10.14.5 && tcp.port == 443host 10.10.14.5 and tcp port 443Inspect bidirectional flow for a single endpoint
Detect TCP SYN Port Scanstcp.flags.syn == 1 && tcp.flags.ack == 0tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-synSpots Nmap -sS sweeps & SYN flood DDoS bursts
Hunt HTTP POST & Auth Flowshttp.request.method == "POST" || http.response.code >= 400tcp port 80 and (((ip[2:2] - ((ip[0]&0xf)<<2)) - ((tcp[12]&0xf0)>>2)) != 0)Extracts form logins, API calls & 4xx/5xx errors
Inspect TLS ClientHello & SNItls.handshake.type == 1 && tls.handshake.extensions_server_nametcp port 443 and (tcp[((tcp[12]&0xf0)>>2)] = 0x16)Identifies destination domain names inside HTTPS
Audit DNS Queries & AXFRdns.flags.response == 0 || dns.qry.type == 252port 53Detects C2 DNS tunneling & zone transfer attempts
Exclude Your Own SSH Session!(tcp.port == 22 && ip.addr == 192.168.1.50)not (tcp port 22 and host 192.168.1.50)Prevents feedback loop when running remote tcpdump
In-Depth ZerosUniverse Tutorial

CEH Module 08: Packet Sniffing & Wireshark Analysis Guide

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Wireshark Display Filter & tcpdump BPF Syntax Builder

01

Choose a Threat Preset or Custom Protocol

Select a pre-built detection profile (e.g., Nmap SYN Scan, TLS ClientHello SNI, ARP Duplicate IP) or pick TCP, UDP, ICMP, DNS, HTTP, TLS, or SMB.

02

Specify Source/Destination IPs, Subnets & Ports

Enter host IPs, CIDR blocks, and port numbers, and choose directional operators (Source, Destination, or Either).

03

Configure TCP Flags & Payload Match Conditions

Toggle SYN, ACK, FIN, RST, PSH, or URG bits and optional payload substring/hex filters (frame contains).

04

Copy Wireshark Filter, tcpdump, or tshark CLI

Paste the Display Filter directly into Wireshark's filter bar or run the generated tcpdump/tshark command on your Linux sensor.

Key Capabilities & Technical Architecture

Dual Wireshark Display + tcpdump BPF Engine

Build your filter visually once and get both the Wireshark GUI display expression (ip.addr == ...) and the equivalent kernel-level tcpdump BPF CLI command simultaneously.

TCP Flag Bitmask & Handshake Selector

Filter half-open SYN scans (tcp.flags.syn == 1 && tcp.flags.ack == 0), Xmas scans, RST teardowns, TCP retransmissions, and zero-window congestion events with visual toggles.

SOC Threat Hunting & Attack Presets

One-click presets for ARP cache poisoning detection, SMBv2/v3 lateral movement, Kerberos AS-REQ roasting, DNS exfiltration (long TXT queries), and cleartext HTTP basic auth.

tshark Field Extraction Command Generator

Automatically generate companion tshark -r capture.pcap -T fields -e ... CLI commands to extract source IPs, SNI hostnames, and URI paths directly to CSV.

Practical Use Cases

PCAP Forensics & Incident Response

Isolate command-and-control beaconing, TLS Server Name Indication (SNI) domains, and lateral movement flows inside multi-gigabyte packet captures.

Production Server Packet Capture (tcpdump)

Craft precise kernel BPF capture filters (-nn -s0 -w) on headless Linux servers so only relevant packets are written to disk during live troubleshooting.

CEH Module 08 & Blue Team Certification Prep

Master the syntax differences between capture-time Berkeley Packet Filters (BPF) and post-capture Wireshark protocol dissectors.

Frequently Asked Questions (FAQs)

What is the difference between a Wireshark Capture Filter (BPF) and a Display Filter?+

A Capture Filter uses libpcap/Berkeley Packet Filter (BPF) syntax (such as 'tcp port 443 and host 10.0.0.5') and discards non-matching packets at the OS kernel driver level before they are recorded. A Display Filter uses Wireshark's rich protocol dissector syntax (such as 'tls.handshake.type == 1 && ip.addr == 10.0.0.5') to hide or show packets non-destructively within an already captured PCAP.

Why should I avoid using 'ip.addr != x.x.x.x' in Wireshark display filters?+

Every IP packet contains two IP addresses (ip.src and ip.dst). The expression 'ip.addr != 10.0.0.1' evaluates to true if EITHER the source OR destination IP is not 10.0.0.1—which matches almost every packet. Always use '!(ip.addr == 10.0.0.1)' to exclude traffic to and from a host.

How do I filter for TCP SYN scans in Wireshark and tcpdump?+

In Wireshark, use 'tcp.flags.syn == 1 and tcp.flags.ack == 0' to view initial connection attempts without ACK replies. In tcpdump BPF syntax, use 'tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn' or 'tcp[13] == 2' to match packets where only the SYN bit (bit 1, value 2) is set in byte 13 of the TCP header.

How can I inspect HTTPS domains in Wireshark when traffic is encrypted?+

Even in TLS 1.3 with encrypted certificates, the initial TLS ClientHello handshake normally includes the Server Name Indication (SNI) extension in cleartext (unless ECH is active). Filter with 'tls.handshake.extensions_server_name' in Wireshark to see every requested HTTPS hostname.

What do the tcpdump flags -nn, -s0, and -vvv do?+

The -nn flag disables both DNS hostname lookups and port-to-service name translation for faster, unambiguous output; -s0 sets the snaplen to 0 (capturing the full packet payload rather than truncating at 68/96 bytes); and -vvv enables maximum protocol decoding verbosity.