C

Networking › Module 3 › Lesson 4

BeginnerModule 3Lesson 4/5

Lab — Wireshark Packet Analysis

Capture and inspect your own traffic with Wireshark—ethically

25 min+41 XP
Module progress4 of 5
DNS query · cyberlium.comDNS response · A 93.184.x.xTLS Client Hello · :443HTTP/2 GET (encrypted)
Wireshark · Frames · Protocol decode

Opening

See the packets behind the apps

Wireshark turns invisible network conversations into readable frames. Analysts use it to confirm DNS answers, spot cleartext HTTP, and verify TLS handshakes. In this lab you capture only your own traffic—never sniff others without permission.

1. Ethics First

Capture only on interfaces and networks you own or are explicitly authorized to monitor. Sniffing traffic on school, office, or public Wi-Fi without approval can violate policy and law. This lab uses your machine, your browser, and your DNS queries.

2. Setup

1. Install Wireshark (wireshark.org) on your VM, lab PC, or WSL with a GUI. 2. Select your active interface (Wi-Fi or Ethernet—not loopback unless testing localhost). 3. Start capture, then generate traffic in another window.

3. Generate and Filter Traffic

Generate traffic (run while capturing)nslookup cyberlium.com curl http://example.com curl -I https://cyberlium.com

nslookup cyberlium.com
curl http://example.com
curl -I https://cyberlium.com

Wireshark display filtersdns http tls.handshake

dns
http
tls.handshake

Click a DNS response and note the A record IP. On an HTTP packet, expand Hypertext Transfer Protocol and read the request line.

4. What to Document

  • DNS query

    Query name, response code, and resolved IPv4 address.

  • HTTP vs HTTPS

    Could you read HTTP headers in cleartext? TLS packets should show encrypted application data.

  • Ports

Complete Wireshark Packet Lab

Capture at least 30 seconds of your own traffic. Apply dns and http or tls filters. Save a screenshot or short notes showing one DNS answer and one HTTPS (TLS) handshake. Store notes in ~/cyberlium-lab/wireshark-notes.txt.

← Previous