← How-Tos
flipper-zero Jul 3, 2026 ◑ 2 views ◯ 2 min read

PCAP Workflow: Capture on Flipper, Analyze in Wireshark

flipper zeropcapwiresharkwifi devboardpacket analysis

Why Move Captures to Wireshark

Flipper's small screen is fine for live monitoring but genuinely limited for deep packet analysis — Wireshark gives you filtering, protocol dissection, statistics, and the ability to actually dig into frame contents at a level Flipper's UI was never meant to provide.

Capturing to PCAP on the Dev Board

With Marauder firmware (see setup guide), most Sniff modes support a "Save PCAP" option that writes captures in standard PCAP format to the Dev Board's SD card (if the Dev Board variant you have includes one) or to Flipper's own storage depending on your firmware build's configuration:

  1. Start the relevant Sniff mode (beacon, probe, deauth detection, or general capture depending on what you're investigating).
  2. Enable PCAP saving from the mode's options before or during capture.
  3. Let it run for your needed capture window, then stop.

Getting the File Off the Device

Opening in Wireshark

File > Open, select the .pcap file — Wireshark will parse and display it as a standard packet capture, fully compatible with any other PCAP source (this is a genuinely standard, widely-supported format, not something Flipper-specific).

Useful Wireshark Filters for WiFi Captures

What You Can Learn From the Analysis

Keeping This Legal

Same rule as everywhere else in this series — capture and analyze traffic on your own network/equipment, or under explicit authorization for a professional engagement. The PCAP format and Wireshark analysis technique are neutral tools; the legality is entirely about whose network you're pointing them at.