
Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.
Wireshark made easy (in your terminal).
Babyshark is a PCAP TUI that helps you answer:
Status: v0.3.0 (alpha).
.pcap / .pcapng viewing works without Wiresharktshark (Wireshark CLI)
Overview is the “start here” dashboard. It summarizes the capture and suggests what to do next.
tshark).How to use it:
D to jump to Domains (hostnames-first).W to jump to What’s weird? (curated detectors).F (or f) to jump to Flows (raw).
Domains groups traffic by hostname so you can start from names instead of 5‑tuples.
How to use it:
s to change the sort mode.c to clear an active subset filter.
What’s weird? is a curated set of detectors meant to answer “what looks broken/slow?” without needing deep Wireshark knowledge.
How to use it:
1–9 to jump-select) and press Enter.c to clear an active subset filter.
Expand / Explain (?) gives plain-English context for what you’re looking at.
? to open Explain.Tip: press h for help and g for glossary.
Grab a binary from GitHub Releases:
git clone https://github.com/vignesh07/babyshark
cd babyshark/rust
cargo install --path . --force
babyshark --help
.pcap / .pcapng and browse:
n / N navigationDL/UL suffix in flow list + download-heavy/upload-heavy/balanced in details (falls back to A>B/B>A when local side is ambiguous)T):
Download a prebuilt binary:
Prereqs:
tsharkgit clone https://github.com/vignesh07/babyshark
cd babyshark/rust
cargo install --path . --force
babyshark --help
cargo install --git https://github.com/vignesh07/babyshark --bin babyshark
tshark (required for --live)tshark is the official Wireshark CLI.
# macOS (Homebrew)
brew install wireshark
Debian/Ubuntu:
sudo apt-get update
sudo apt-get install -y tshark
Fedora:
sudo dnf install -y wireshark-cli
Arch:
sudo pacman -S wireshark-cli
Verify:
tshark --version
tshark -D
Permissions note: live capture may require elevated permissions (sudo, dumpcap caps, or being in the wireshark group). If babyshark prints a permission error, follow the guidance it outputs.
babyshark updated in git but my command still runs old behaviorIf you installed with cargo install, you need to reinstall after pulling:
cd babyshark/rust
cargo install --path . --force
Try running with sudo:
sudo babyshark --live en0
If that works, you likely need to configure capture permissions (dumpcap, wireshark group, etc.) on your OS.
ips=0 for everythingThis often happens when DNS answers aren’t visible (DoH/DoT or cached). Babyshark will still show Observed IPs (from flows) using TLS SNI / HTTP Host hints when available.
babyshark --pcap ./capture.pcap
babyshark --list-ifaces
babyshark --live en0
babyshark --live en0 --dfilter "tcp.port==443"
babyshark --live en0 --write-pcap /tmp/live.pcapng
These are text-only examples of what you’ll see in the TUI. IPs/domains are anonymized.
PCAP Viewer
babyshark Overview flows:114 packets:4227 tcp:on udp:on q=—
Overview (D domains, W weird, F flows)
In plain English
Packets: 4227 Flows: 114 Top talker: 10.0.0.6 (2711.9KB) Top talker (pkts): 10.0.0.6 (4046 pkts)
Live: 88s pps~14.6 dropped~0 | last: Capturing on 'Wi‑Fi: en0'
pps: ▁▁▂▂▃▄▅▆▆▇▆▅▄▃▂▂▁ (max 1372/bucket)
Top flow (bytes): UDP 10.0.0.6:57315 ↔ 203.0.113.123:443 (1359.3KB)
Top flow (pkts): UDP 10.0.0.6:57315 ↔ 203.0.113.123:443 (1284 pkts)
What should I click?
• Domains (human view) (press D)
• Weird stuff (troubleshoot) (press W)
• Flows (raw) (press F)
• Timeline (Gantt + Scatter) (press T)
↳ Detected: High-latency flows (rough) (29 flows)
Domains (Enter show flows, s sort (conn/bytes/fail), c clear, Esc back)
1 wikipedia.com conn=9 bytes=21.0KB q=9 r=6 fail=0 ips=2
❯ 2 chat.openai.com conn=5 bytes=28.2KB q=5 r=3 fail=0 ips=2
Domain details
chat.openai.com