
A simple, reliable and reasonably fast network capture analyzer.
Sharker is a powerful and extensible tool for extracting valuable data from PCAP files or from live interfaces. It leverages the power of tshark to efficiently parse network captures and applies a flexible filtering system to pinpoint and extract juicy information.
.pcap files, directories of captures, or even live network traffic from an interface.apt-get install tshark, brew install wireshark).requirements.txt and can be installed with pip/pipx.You can install Sharker using pipx (recommended) or a standard pip and venv environment.
pipx (Recommended)# Install from this repository
pipx install git+https://github.com/synacktiv/sharker.git
# Verify the installation
sharker -h
pip and venv# Clone the repository
git clone https://github.com/synacktiv/sharker.git
cd sharker
# Create and activate a virtual environment
python3 -m venv venv
source venv/bin/activate
# Install Sharker
pip install .
# Verify the installation
sharker -h
The basic syntax for Sharker is:
sharker [OPTIONS] [PCAP_FILE(s)]
| Option | Description |
|---|---|
-i, --interface <IFACE> | Capture live traffic from a network interface (e.g., eth0). |
-d, --pcap-dir <DIR> | Analyze all PCAP files in a directory. |
-o, --output-dir <DIR> | Specify the directory for output files (default: ./sharker_out). |
-m, --output-mode <MODE> | Set the output mode: file, console, both, or develop (default: both). |
-u, --unique | Output only unique results. |
-F, --fast | Fastest configuration (do not affect filter selection). |
-A, --all | Enable all filters, will be slower. |
| Option | Description |
|---|---|
-c, --categories <CATS> | A comma-separated list of filter categories to run (e.g., creds,http). |
-nc, --not-categories <CATS> | A comma-separated list of filter categories to exclude (e.g., heavy). By default, heavy is excluded. |
-f, --filters <FILTERS> | A comma-separated list of specific filters to run. |
-nf, --not-filters <FILTERS> | A comma-separated list of specific filters to exclude. |
-L, --list-all-filters | Display a list of all available filters and their descriptions. |
-Lc, --list-all-filter-categories | Display a list of all available filter categories. |
-l, --list-filters | Show the filters that will be active with the current command-line options. |
-v, --verbose | Enable verbose logging for debugging. |
1. Analyze a single PCAP and save the results:
sharker my_capture.pcap
This will run all filters except those in the heavy category and save the output to the sharker_out/ directory. Filters in the creds category will also be printed to stdout.
2. Apply all filters and try to go as fast as possible:
sharker -A -F my_captures.pcap
This will apply all filters and output everything to files, no results will be printed on the console.
3. Analyze a directory of PCAPs, focusing on credentials:
sharker -d /path/to/pcaps -c creds
This command processes all PCAP files in the specified directory, but only runs the filters in the creds category.
4. Capture live traffic and print HTTP-related information to the console:
sudo sharker -i eth0 -c http -m console
This will capture traffic from the eth0 interface, run only the http category filters, and print all results directly to the terminal.
5. List all available filters:
sharker -L
$ sharker -h
Usage: sharker [OPTIONS] [PCAP[ PCAP[ ...]]
Sharker: A reasonably fast network protocol analysis tool with extensible
filters.