Display Filter
Definition
A Wireshark filter expression applied to an already-captured PCAP file to show only packets matching specified criteria. Display filters do not delete non-matching packets, preserving the full capture. Syntax differs from BPF capture filter syntax.
- Applies to
- Already-captured PCAP data
- Effect on packets
- Hides non-matching packets, does not delete them
- Tool
- Wireshark
- Distinct from
- BPF capture filter syntax
Common questions
Why does a display filter matter for evidence handling?+
Because it never deletes packets, an examiner can narrow the view for analysis or a report screenshot while the underlying PCAP remains complete and unaltered, which matters for chain-of-custody and for opposing-side review.
Can a display filter and a capture filter use the same syntax?+
No. Capture filters use BPF syntax applied while traffic is being recorded, while display filters use Wireshark's own expression language applied afterward, so a filter string written for one will often not work in the other.
Related terms
- Artefact Carving
- Extracting embedded content from raw data by locating known file signatures (magic bytes) at byte boundaries. In PCAP analysis, this means reassembling...
- Beaconing
- Periodic outbound connections from a compromised host to a command-and-control server, typically at regular intervals. The regularity of the interval, measured in...
- PCAP
- Packet capture file. The standard format for storing captured network frames, originally defined by the libpcap library. Each record contains the raw...
- Protocol Dissector
- A software component in a packet analyser that recognises a specific protocol and parses its header fields into named, readable values. Wireshark...
- Stream Reassembly
- The process of collecting all the TCP segments belonging to a single connection and reordering them by sequence number to reconstruct the...