# Wireshark Display Filter Starter Set

Use on traffic you are authorized to inspect.

| Goal | Display filter |
|---|---|
| DNS queries | `dns.flags.response == 0` |
| DNS answers | `dns.flags.response == 1` |
| HTTP requests | `http.request` |
| TLS handshakes | `tls.handshake` |
| Failed TCP handshakes | `tcp.flags.syn == 1 && tcp.flags.ack == 0` |
| TCP resets | `tcp.flags.reset == 1` |
| Large outbound transfers | `ip.src == <host> && frame.len > 1200` |
| One endpoint | `ip.addr == <ip>` |
| Suspicious cleartext auth strings | `frame matches "(?i)(password|passwd|authorization|token)"` |
| SMB traffic | `smb2 || smb || nbss` |
| Kerberos | `kerberos` |
| DHCP | `bootp` |

## Workflow
1. Start broad with endpoints and protocols.
2. Mark known-good infrastructure such as DNS, proxies, and update servers.
3. Pivot from suspicious DNS or TLS SNI to endpoint logs.
4. Export selected packets with case notes, not entire captures, unless needed.
