Tshark | Zeek Copy & Paste
I don't know why but I like this more than wireshark itself
Tshark
Export file from the pcap
tshark -r ${file} --export-object ${protocol},${path_for_the_output}Get User-Agent from a pcap file
tshark -r sample.pcap -T fields -e http.user_agent tcp.dstport==80 | sort | uniq -c | sort -n Zeek
Check SSL Certificate
Unique DNS
Last updated