Babyshark is an open-source terminal UI (TUI) for analyzing PCAP network captures, built in Rust. It offers a flows-first approach to network inspection without requiring Wireshark knowledge. Key features include offline PCAP/PCAPng viewing, live capture via tshark, a domain-grouped traffic view, curated anomaly detectors

7m read timeFrom github.com
Post cover image
Table of contents
QuickstartFeaturesInstallInstall tshark (required for --live )TroubleshootingUsageExample screens (sanitized)Keybindings (TUI)Output filesRoadmapLicense

Sort: