Agregar usuario al grupo wireshark.
Copiar sudo su
usermod -a -G wireshark < usernam e >
Listar interfaces.
Iniciar captura con tarjeta inalámbrica en modo monitor.
Copiar wireshark -i < interfac e > -k
wireshark -i wlan0 -k
Iniciar captura con interfaz virtual en modo monitor.
Copiar wireshark -i < virtual-interfac e > -k
wireshark -i wlan0mon -k
Iniciar captura con filtro.
Copiar wireshark -i < interface-mo n > -k -f "<filter>"
wireshark -i wlan0mon -k -f "((wlan addr1 <BSSID>) or (wlan addr2 <BSSID>) or (wlan addr3 <BSSID>) or (wlan addr4 <BSSID>)) and not (subtype beacon) and not (type ctl) and not (subtype probe-req) and not (subtype probe-resp)"
Captura desde standard output (stdout).
Copiar # tcpdump
tcpdump -U -w - -i < interface-mo n > | wireshark -k -i -
tcpdump -U -w - -i wlan0mon | wireshark -k -i -
# dumpcap
dumpcap -w - -P -i < interface-mo n > | wireshark -k -i -
dumpcap -w - -P -i wlan0mon | wireshark -k -i -
# tshark
tshark -w - -i < interface-mo n > | wireshark -k -i -
tshark -w - -i wlan0mon | wireshark -k -i -
Captura remota.
Copiar # SSH + tcpdump
ssh < use r > @ < IP-addres s > "sudo -S tcpdump -U -w - -i <interface-mon>" | sudo wireshark -k -i -