Get the latest tech news
Wireshark 4.6.0 Supports macOS Pktap Metadata (PID, Process Name, etc.)
Four years after my post on doing network captures on macOS with Process ID, Wireshark 4.6.0 has been released which includes support for parsing this extra metadata, including the process info. So how do you do it? Easy! You just need the pktap interface parameter.
None
Or read this on Hacker News