Termshark is a terminal interface for tshark, inspired by Wireshark, for examining saved packet captures and live traffic. It reads pcap files and can sniff live interfaces when tshark permits; both files and live captures can be filtered with Wireshark display filters. Users can reassemble and inspect TCP and UDP flows, search packets, copy packet ranges to the clipboard, and view conversations for Ethernet, IPv4, IPv6, UDP, and TCP. Version 2.4 added packet search and profiles for colors and columns. Termshark is intended for people debugging on remote machines who want to inspect a large capture without copying it to a desktop. The project lists Linux, macOS, BSD variants, Windows, and Android through Termux, with precompiled executables available through GitHub releases. Terminal modes include 16-color, 256-color, and truecolor. Termshark is free and MIT licensed, but packet analysis requires tshark version 1.10.2 or newer in the PATH. The project also notes that tshark has more features than Termshark currently exposes. Its user guide estimates that loaded packet data uses approximately 10 MB of RAM per 1,000 packets.
Who it is for
Termshark suits people debugging on remote machines who need to inspect packet captures in a terminal without moving them to a desktop. It is also relevant to users who need to examine live traffic where tshark permits capture.
What is good
- Reads pcap files and can sniff live interfaces.
- Supports Wireshark display filters.
- Can reassemble and inspect TCP and UDP flows.
- Runs on Linux, macOS, BSD, Windows, and Termux.
- Free and MIT licensed.
What to know first
- Requires tshark 1.10.2 or newer in PATH.
- Some tshark features are not exposed.
- Loaded data uses approximately 10 MB RAM per 1,000 packets.
Freedom251 review
Termshark: the full review
Termshark offers terminal-based capture inspection, filtering, and flow analysis, including for remote-machine workflows. It depends on tshark and exposes less functionality than tshark itself.
Termshark is a terminal interface for inspecting packet captures through tshark. It suits people debugging on remote machines who want to examine a large capture in place; its reliance on tshark and narrower feature set make it a focused alternative, not a replacement for tshark.
Overview
Termshark brings common packet-analysis work into a terminal workflow. It reads pcap files and can sniff live interfaces when tshark has permission, which makes it useful both for reviewing saved traces and investigating traffic where it is captured. The remote-machine use case is its clearest advantage: a large pcap can be inspected without copying it to a desktop.
That convenience comes with a dependency and a boundary. Packet analysis requires tshark 1.10.2 or newer in the PATH, and tshark itself exposes more features. Termshark is a good fit when its terminal interface covers the task; users who need tshark’s full functionality should work with tshark directly.
Key features
- Capture and pcap analysis: Read pcap files or sniff live interfaces. Live capture depends on tshark being permitted, so the interface does not remove operating-system or configuration restrictions.
- Display filters: Apply Wireshark display filters to saved captures and live traffic, making it possible to narrow packet data without leaving the terminal.
- Flow and conversation inspection: Reassemble and inspect TCP and UDP flows. The conversation view supports Ethernet, IPv4, IPv6, UDP, and TCP, a defined set that may not cover every protocol a user wants to examine.
- Search, copying, and profiles: Packet search and profiles for colors and columns support finding relevant traffic and tailoring the view. Users can also copy packet ranges to the clipboard from the terminal.
- Terminal display: Support for 16-color, 256-color, and truecolor modes gives it options across terminals with different color capabilities.
Loaded packet data uses approximately 10 MB of RAM per 1,000 packets, a useful consideration when working with large traces on a resource-constrained remote machine.
Pricing
Termshark is free: its plan costs 0.00 USD per free and includes packet analysis subject to the tshark dependency. There are no paid tiers to weigh against that core offering. The practical cost is setup: tshark 1.10.2 or newer must be available in the PATH, and some tshark features are not exposed in Termshark.
Platforms
The project provides downloads for Linux, macOS, BSD variants, Windows, and Android through Termux. Precompiled executables are available through GitHub releases. Although the directory’s platform coverage includes these systems, Android use is specifically through Termux; the software depends on tshark, tcell, and gowid. Setup help, bug reports, and feature requests are directed to GitHub.
Who it's for
Termshark is aimed at people debugging on remote machines who need to inspect captures without transferring them to a desktop. It also suits users who prefer terminal-based pcap review, display filtering, and flow inspection. It is less suitable when the task depends on tshark functionality that Termshark does not expose, or when tshark cannot be installed or used with the required permissions.
Pros and cons
- Pro: It can inspect a large pcap on the machine where it resides, avoiding a transfer to a desktop for remote debugging.
- Pro: It combines offline pcap reading, permitted live capture, display filters, packet search, and TCP/UDP flow inspection in a terminal interface.
- Pro: The software is free and MIT licensed, with precompiled downloads for several platforms.
- Con: Packet analysis depends on a compatible tshark installation in the PATH, adding a prerequisite to setup.
- Con: It exposes less functionality than tshark, and live capture still requires permission.
- Con: The conversation view is limited to Ethernet, IPv4, IPv6, UDP, and TCP; loaded data also uses about 10 MB of RAM per 1,000 packets.
Alternatives
For a broader set of packet-analysis workflows, compare the network packet capture software directory.
- Malcolm is a free, self-hosted option for readers who want packet-analysis software across web and API platforms as well as desktop operating systems.
- NetworkMiner is a freemium, GPLv2 open-source option for readers who prefer its managed C# and .NET Framework implementation.
- Sniffnet is a free, open-source option for readers looking for software that runs on Linux, macOS, or Windows.
- tcpdump is a free, BSD-licensed alternative for readers who prefer that license; capture permission depends on the operating system and configuration.
- TShark is the direct alternative for readers who want tshark’s broader feature set rather than Termshark’s interface.
- Wireshark is a free option for readers who prefer its full version over a terminal interface.
- Arkime is a free, open-source alternative for readers seeking self-hosted software with web and API platforms.
- PCAPdroid is an Android-only freemium alternative for readers who want core network monitoring and capture on Android.
Verdict
Choose Termshark if you need free, terminal-based capture inspection on the machine where traffic was recorded, especially for remote debugging without moving large pcaps. Look elsewhere if you need tshark’s full feature set, cannot meet its runtime dependency, or need live capture without the required permissions.
Termshark plans and pricing
All plansCompared on network packet capture software
- Free plan
- Yes
- Live capture
- Yes
- Offline trace analysis
- Yes
- Display filters
- Yes
- Capture file formats
- pcap
- Command-line capture
- Yes
- Supported platforms
- Linux, macOS, BSD variants, Android (Termux), Windows

