Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
sharker — A simple, reliable and reasonably fast network capture analyzer. | Kitploit
Tools/GitHubGitHub/synacktiv/sharker
Packet Sniffing & AnalysisPassword CrackingInformation GatheringWeb SecurityNetwork SecurityDigital Forensics
GitHubsynacktiv/sharker

sharker

A simple, reliable and reasonably fast network capture analyzer.

View Repository
331204 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Sharker: where Wireshark ends, we begin

Sharker is a powerful and extensible tool for extracting valuable data from PCAP files or from live interfaces. It leverages the power of tshark to efficiently parse network captures and applies a flexible filtering system to pinpoint and extract juicy information.

Key Features

  • Extensible Filtering: Create Python-based filters to extract any data from network packets.
  • Powerful Filtering Engine: Selectively enable or disable filters and filter categories to fine-tune and speed up your analysis.
  • Multiple Input Sources: Analyze .pcap files, directories of captures, or even live network traffic from an interface.
  • Flexible Output: Save results to organized text files, print to the console, or both.

Requirements

  • tshark: The command-line companion to Wireshark is essential. You can typically install it through your system's package manager (e.g., apt-get install tshark, brew install wireshark).
  • Python 3
  • Python libraries: The required libraries are listed in requirements.txt and can be installed with pip/pipx.

Installation

You can install Sharker using pipx (recommended) or a standard pip and venv environment.

Using pipx (Recommended)

# Install from this repository
pipx install git+https://github.com/synacktiv/sharker.git

# Verify the installation
sharker -h

Using pip and venv

# Clone the repository
git clone https://github.com/synacktiv/sharker.git
cd sharker

# Create and activate a virtual environment
python3 -m venv venv
source venv/bin/activate

# Install Sharker
pip install .

# Verify the installation
sharker -h

Usage

The basic syntax for Sharker is:

sharker [OPTIONS] [PCAP_FILE(s)]

Common Options

Main options

OptionDescription
-i, --interface <IFACE>Capture live traffic from a network interface (e.g., eth0).
-d, --pcap-dir <DIR>Analyze all PCAP files in a directory.
-o, --output-dir <DIR>Specify the directory for output files (default: ./sharker_out).
-m, --output-mode <MODE>Set the output mode: file, console, both, or develop (default: both).
-u, --uniqueOutput only unique results.
-F, --fastFastest configuration (do not affect filter selection).
-A, --allEnable all filters, will be slower.

Filtering options

OptionDescription
-c, --categories <CATS>A comma-separated list of filter categories to run (e.g., creds,http).
-nc, --not-categories <CATS>A comma-separated list of filter categories to exclude (e.g., heavy). By default, heavy is excluded.
-f, --filters <FILTERS>A comma-separated list of specific filters to run.
-nf, --not-filters <FILTERS>A comma-separated list of specific filters to exclude.
-L, --list-all-filtersDisplay a list of all available filters and their descriptions.
-Lc, --list-all-filter-categoriesDisplay a list of all available filter categories.
-l, --list-filtersShow the filters that will be active with the current command-line options.
-v, --verboseEnable verbose logging for debugging.

Example Usage

1. Analyze a single PCAP and save the results:

sharker my_capture.pcap

This will run all filters except those in the heavy category and save the output to the sharker_out/ directory. Filters in the creds category will also be printed to stdout.

2. Apply all filters and try to go as fast as possible:

sharker -A -F my_captures.pcap

This will apply all filters and output everything to files, no results will be printed on the console.

3. Analyze a directory of PCAPs, focusing on credentials:

sharker -d /path/to/pcaps -c creds

This command processes all PCAP files in the specified directory, but only runs the filters in the creds category.

4. Capture live traffic and print HTTP-related information to the console:

sudo sharker -i eth0 -c http -m console

This will capture traffic from the eth0 interface, run only the http category filters, and print all results directly to the terminal.

5. List all available filters:

sharker -L

Help output

Click to see full help output
$ sharker -h
Usage: sharker [OPTIONS] [PCAP[ PCAP[ ...]]

  Sharker: A reasonably fast network protocol analysis tool with extensible
  filters.
Download Tool