Wireshark logo

Wireshark Recorded Package Source

Direct package links and installation notes for Windows/macOS/Linux

Developer Tools · v4.6.8 · Free (GPL)

Network protocol analyzer and packet capture

Source record, not a product review. Automated checks can confirm URL availability but not package safety, installation behavior, or offline operation. Catalog maintained by .
License: Free (GPL)
Size: 98.9 MB (Windows x64)
Platforms: Windows macOS Linux

Download summary

Wireshark is a developer tool for Windows/macOS/Linux, published by Wireshark Foundation. A direct package URL is recorded below. The host may be the publisher, a release repository, a CDN, or another distribution source documented by the publisher. Some packages still fetch optional components during setup. The recorded publisher site is wireshark.org. We do not host or modify installer files.

Sources and identity

External references used to identify the product and publisher. These links do not prove that we installed the package.

Wikipedia article Source on GitLab SHA-256 listed in catalog

Publisher documentation

These references support the package and behavior notes. Documentation checks are separate from the recorded URL-check date and do not represent an installation test.

Choose a package

Saved-file analysis or live capture

For saved captures, the analyzer can work without a capture driver. For live Windows capture, plan a compatible and appropriately licensed Npcap installation.

Wireshark’s silent EXE setup does not install Npcap. The portable and MSI packages do not remove the driver or permission requirements. The listed Linux TAR.XZ is source code to build, not a ready-to-run Linux application.

Package guidance is based on the linked documentation, checked 11 September 2026. No installation test is claimed.

Publisher SHA-256 reference values

Compared all six recorded values with the publisher’s signed release announcement. The OpenPGP signature and local binaries were not independently verified. Compared on 11 September 2026 with the publisher’s reference.

Wireshark-4.6.8-x64.exe
8eba737cb6875d9b3709228d37893f71125bdc50d7148e24d9cdc755259e9c3a
Wireshark-4.6.8-arm64.exe
d23b030f5a18394b262fa6686f985f1cc2129be5e3077e378322a2cb78626e0e
Wireshark-4.6.8-x64.msi
779ee66f846376942a3b631a78bba8c3d509697d07743349e1893056211d05e3
WiresharkPortable64_4.6.8.paf.exe
d6cf5056586a0156c8634a9d9b3097e60a8dda408b889c9afc4445ec2b18d581
Wireshark 4.6.8.dmg
7de945ed1ba324259ba7e3b2ca2fe11a854cf48a33dc6d4423dd531e466a1f3a
wireshark-4.6.8.tar.xz
c0f1ccf217bc0d3b51a9c03ea178b0f7df682e475da26a2d21cd4a1bdd9579d0

Compare only with the exact named package. A matching hash alone does not establish publisher identity or package safety.

Download options

Recorded package links, store pages, and browser extensions where available.

Scroll the table sideways to compare packages and reach each download link.

Platform Build Architecture Package Action Notes
Windows

ARM64

Wireshark 4.6.8 Windows ARM64 installer

ARM64 EXE Download file Official Windows ARM64 installer from a Wireshark download mirror
Windows

EXE

Wireshark 4.6.8 Windows x64 installer

64-bit EXE Download file Interactive installer can offer separately licensed Npcap; silent Wireshark setup does not install it
Windows

MSI

Wireshark 4.6.8 Windows x64 MSI

64-bit MSI Download file Official MSI; Npcap must be provisioned and licensed separately for live capture
Windows

Portable

Wireshark 4.6.8 Windows portable package

64-bit EXE Download file PortableApps package; a compatible capture driver is still required for live capture
macOS

Universal

Wireshark 4.6.8 macOS universal DMG

Universal DMG Download file Official universal macOS disk image
Linux

Source archive

Wireshark 4.6.8 source tarball

Source TAR.XZ Download file Upstream source archive, not a prebuilt Linux application package

Verification scope

A direct package URL is recorded above. We have not independently installed every listed build or confirmed that setup remains fully offline.

We do not host software files. Links may resolve to a publisher domain, its release repository, app store, CDN, or a documented distribution host — confirm the final hostname, publisher signature, version, and architecture before deployment. Recorded URLs last checked 30 August 2026; content last updated 11 September 2026.

What Wireshark does

Wireshark is a GPL-licensed protocol analyzer for inspecting saved capture files and, with an appropriate capture mechanism and permissions, recording live network traffic. It decodes protocol fields, applies capture and display filters, follows supported streams, and provides conversation, endpoint, hierarchy, and I/O statistics. Protocol dissection does not guarantee that encrypted application content is readable: following TLS normally requires suitable session secrets or private-key conditions documented by Wireshark, and decryption coverage depends on the protocol and cipher configuration.

This record pins Wireshark 4.6.8 Windows x64 and ARM64 installers, the Windows x64 MSI and portable package, a universal macOS disk image, and the upstream source tarball. The Linux row is source code, not a distribution-native binary; Linux users should normally follow their distribution or Wireshark's platform guidance. The project announcement publishes the SHA-256 values transcribed below and an OpenPGP-signed release message. This audit did not validate that signature or execute the packages.

On Windows, the interactive EXE can offer the separately licensed Npcap capture driver. Wireshark documents that silent installation of its EXE does not install Npcap; without a compatible capture driver, Wireshark can still open saved captures but cannot perform normal live capture. The MSI and portable package also do not erase driver, privilege, policy, or redistribution requirements. Npcap licensing can restrict redistribution and some organizational deployments, so administrators must review its current terms separately.

Packet capture can expose credentials, tokens, personal data, payloads, and unrelated users' traffic. Capture only traffic you are authorized to inspect, minimize capture privileges and scope, and protect or sanitize files before sharing. Running the graphical interface with elevated privileges is not a substitute for a least-privilege capture setup.

Reference images

Wireshark Developer Tools preview card
Wireshark — Developer Tools

Captions describe the visible contents. Reference images are not installation-test results and may show older releases or other platforms.

Product features

  • Protocol dissection for live or saved traffic, subject to capture access and format support
  • Capture and display filters with conversation, endpoint, hierarchy, and I/O statistics
  • Stream following; encrypted content requires applicable secrets and supported decryption conditions
  • Windows live capture depends on a compatible Npcap installation and privileges
  • Capture files can contain sensitive data and require controlled handling

Installation notes

Grouped by the package types recorded on this page — not a claim that every listed build was independently tested on every supported platform.

Windows Windows installer (EXE)

  1. 1

    Download the recorded file (Wireshark-4.6.8-x64.exe). If it has a digital signature, inspect the signer and validation result in Properties → Digital Signatures. If no signature is present, follow the publisher's documented verification method; a missing signature does not authenticate the file.

  2. 2

    Check any Windows warning before proceeding. A SmartScreen reputation warning is not signature verification; stop if the publisher is unexpected or the file is reported as malicious.

  3. 3

    Follow the publisher's setup prompts to finish; options vary by release, so review each screen rather than clicking through.

Windows Windows installer (MSI)

  1. 1

    Download the recorded file (Wireshark-4.6.8-x64.msi); MSI packages install through Windows Installer. Required privileges depend on the package's supported user or machine scope.

  2. 2

    Run it interactively, or deploy silently with msiexec /i and the vendor's documented properties for managed rollouts.

macOS macOS disk image (DMG)

  1. 1

    Open the disk image and follow the publisher's instructions for its contents. It may contain an app to copy to Applications or a separate installer.

  2. 2

    Check first-launch security prompts. For damaged, revoked, or unverified software, stop and check the publisher's current package and Apple's guidance before proceeding.

Linux Source code archive (build required)

  1. 1

    This archive contains source code, not a ready-to-run program — do not expect an installer inside.

  2. 2

    Building it requires the project's compiler toolchain and development dependencies; follow the publisher's own build documentation.

  3. 3

    If you do not intend to compile, use your distribution's package or one of the prebuilt options listed above instead.

More Developer Tools Source Guides

View all Developer Tools

Also Popular on OfflineInstallerSetup

Browse all software