Comment by PranaFlux

Comment by PranaFlux 3 days ago

0 replies

Absolutely!

It's really a tshark wrapper to make it available for LLMs so any capture filter will work. The display filter also accepts any Wireshark accepted filter.

You can also "just" use it to analyse a pcap if you don't need to record traffic as well as pass an SSLKEYLOG file for the decryption.