Operator tip · wireshark
HTTP POSTs only
Display filter: http.request.method == "POST". Combine with ip.addr== your lab target.
Guide
A raw capture is a firehose. Display filters turn it into a story about the requests that usually carry credentials, forms, and API mutations.
Why it matters
Most interesting lab traffic is POST (or PUT/PATCH). Filtering to POSTs — and scoping to your target IP — cuts noise from CDN chatter, images, and keep-alives so you can find the auth form or the JSON body that matters.
How-to
http.request.method == "POST" http.request.method == "POST" && ip.addr == 10.10.10.50 http.request.uri contains "login"
- Capture on the right interface (VPN/tun vs eth).
- Remember HTTPS payloads stay opaque without keys — use this on cleartext lab HTTP or decrypt when you own the certs.
- Export selected packets → Follow HTTP stream for the full conversation.