Get the latest tech news

Wireshark 4.6.0 Supports macOS Pktap Metadata (PID, Process Name, etc.)


Four years after my post on doing network captures on macOS with Process ID, Wireshark 4.6.0 has been released which includes support for parsing this extra metadata, including the process info. So how do you do it? Easy! You just need the pktap interface parameter.

None

Get the Android app

Or read this on Hacker News

Read more on:

Photo of PID

PID

Photo of process name

process name

Photo of wireshark 4.6.0

wireshark 4.6.0

Related news:

News photo

What Is PID 0?