Introduction to Ethereal (v.0.9.9), The Open Source Network-Protocol Analyzer
6
Ethereal
...Features
• Interactive GUI facility for building display filters
• Distributions include text-based interface (tethereal)
similar to tcpdump, programmatic capture-editor and
converter (editcap), manpages for Unix and Linux (or
via web for Windows)
• Analysis of live or saved network traces (packets can
be examined while capture is active)
• Prints captures as plain text or postscript to file or
printer
• Updated often (1 - 3 month intervals) with new
protocol decodings or enhancements to existing
decoders