Operator tip · wireshark

Follow the stream

Right-click → Follow → TCP/HTTP Stream. Rebuild the conversation instead of squinting at frames.

easy pcapwiresharktcp
/wireshark/ · /tips/wireshark-follow-stream/

Guide

Individual frames are packets. Applications speak conversations. Follow Stream rebuilds the client/server dialogue so you can read headers and bodies like a proxy history.

Why it matters

Squinting at hex in frame 847 while the POST body lives across multiple TCP segments is how operators miss flags in cleartext labs. Stream view is the human interface to the capture.

How-to

  1. Find any packet in the conversation (filter helps).
  2. Right-click → Follow → TCP Stream (or HTTP Stream when decoded).
  3. Toggle client/server colors; search inside the stream for LLZ{, cookies, or tokens.
  4. Save the stream as ASCII for notes.
# After Follow → HTTP Stream
# Look for: Set-Cookie, Authorization, JSON bodies, redirects