Wireshark

Wireshark Foundation and contributors · Inspect network packets, capture traffic and analyze protocols with filters, statistics and companion command-line tools.

CaskNetworkingAuto-updatesApple silicon · Intel
From homebrew/cask
30-day installs2,379#92 in App
1-year installs51.3KLast 365 days
Latest version4.6.92 days ago · Oct 7
Download size147MBarm64 / x86_64 · dmg
Release cadenceMonthly1 release in 30 days

About

Wireshark is an open-source network protocol analyzer for troubleshooting, development and education. Network engineers, administrators and developers use it to inspect packet captures, understand protocol behavior and investigate communication problems.

Features

  • Capture traffic on supported interfaces or open existing capture files.
  • Decode packet fields and inspect bytes with protocol-aware views.
  • Narrow investigations with capture and display filters.
  • Explore conversations, statistics and supported object exports.
  • Use companion command-line tools such as tshark, dumpcap and editcap.

Install and start on macOS

Install with brew install --cask wireshark-app, or open the official DMG and drag Wireshark.app to Applications. To capture live packets, install the included ChmodBPF launch daemon as described in the Mac installation guide. Opening a capture file and capturing live traffic are different workflows; capture permissions must be configured for live acquisition.

The Homebrew cask installs the ChmodBPF and system-path packages and links companion tools. It explicitly conflicts with the separate wireshark-chmodbpf cask because the application cask already provides that component. It declares no additional formula dependency. Packet capture still depends on the interface, permissions and supported capture methods.

Start by selecting an interface or opening a capture file, then apply a filter and inspect packet details. Captures can contain private credentials or payloads; handle files according to the requirements of the network you are analyzing.

Systems and resources

Wireshark 4.6 official Mac installers are universal for Intel and Apple Silicon. The 4.6 release packages use Qt 6.9.3, and tagged build logic requires macOS 12 or later for Qt 6.8 and newer. The user guide states that 4.4 was the last branch supporting macOS 11; its introductory general statement should not be mistaken for 4.6 compatibility with macOS 11.

Windows packages and Linux/UNIX/BSD distributions are also available. Capture drivers and package dependencies differ by platform; Windows capture uses Npcap, while Mac capture setup uses ChmodBPF. Optional external capture sources may need additional tools or credentials. No official native iOS or Android GUI was established.

The user guide gives approximately 500 MB RAM and 500 MB available storage as a starting point for small to medium captures, with more required for large files. A fast processor and sufficient memory/storage matter on busy networks; capture files add substantial storage. These are workload guidelines, not a promise that every capture fits in those amounts.

The current official universal 4.6.9 DMG reports 147,277,050 bytes. This is download size, not installed storage or future capture space. The official documentation screenshot shows Mac interface selection and capture filtering; it is a documentation example rather than an exact-release capture.

Account, fees and license

Wireshark is free and open source; the tagged COPYING file contains GNU GPL version 2. Local capture-file analysis does not require a Wireshark account or subscription. Training, certification, commercial support and third-party tools can have separate costs. Follow project and bundled component license terms when redistributing.

Sources: Official project, Mac installation, System requirements, 4.6.0 package changes, Tagged build requirements, Source and license.

New What’s new in 4.6.9 Oct 7 · OpenNavo editorial

  • ChangesRepair profile-import possible code execution and parser crashes.

An open-source interface for Homebrew. Installs run through the macOS app or the brew command.

© 2026 OpenNavo