Windows installer names contain the platform and version. For example, Wireshark-win64-3.5.0.exe installs Wireshark 3.5.0 for 64-bit Windows. The Wireshark installer includes Npcap which is required for packet capture.
Simply download the Wireshark installer from https://www.wireshark.org/download.html and execute it. Official packages are signed by the Wireshark Foundation, Inc.. You can choose to install several optional components and select the location of the installed package. The default settings are recommended for most users.
On the Choose Components page of the installer you can select from the following:
Plugins & Extensions - Extras for the Wireshark and TShark dissection engines
Tools - Additional command line tools to work with capture files
By default Wireshark installs into %ProgramFiles%\Wireshark
on 32-bit Windows
and %ProgramFiles64%\Wireshark
on 64-bit Windows. This expands to C:\Program
Files\Wireshark
on most systems.
The Wireshark installer contains the latest Npcap installer.
If you don’t have Npcap installed you won’t be able to capture live network traffic but you will still be able to open saved capture files. By default the latest version of Npcap will be installed. If you don’t wish to do this or if you wish to reinstall Npcap you can check the Install Npcap box as needed.
For more information about Npcap see https://nmap.org/npcap/ and https://gitlab.com/wireshark/wireshark/wikis/Npcap.
For special cases, there are some command line parameters available:
/S
runs the installer or uninstaller silently with default values. The
silent installer will not install Npcap.
/desktopicon
installation of the desktop icon, =yes
- force installation,
=no
- don’t install, otherwise use default settings. This option can be
useful for a silent installer.
/quicklaunchicon
installation of the quick launch icon, =yes
- force
installation, =no
- don’t install, otherwise use default settings.
/D
sets the default installation directory ($INSTDIR), overriding InstallDir
and InstallDirRegKey. It must be the last parameter used in the command line
and must not contain any quotes even if the path contains spaces.
/NCRC
disables the CRC check. We recommend against using this flag.
/EXTRACOMPONENTS
comma separated list of optional components to install.
The following extcap binaries are supported.
androiddump
- Provide interfaces to capture from Android devices
ciscodump
- Provide interfaces to capture from a remote Cisco router through SSH
randpktdump
- Provide an interface to generate random captures using randpkt
sshdump
- Provide interfaces to capture from a remote host through SSH using a remote capture binary
udpdump
- Provide an UDP receiver that gets packets from network devices
Example:
> Wireshark-win64-wireshark-2.0.5.exe /NCRC /S /desktopicon=yes /quicklaunchicon=no /D=C:\Program Files\Foo > Wireshark-win64-3.3.0.exe /S /EXTRACOMPONENTS=sshdump,udpdump
Running the installer without any parameters shows the normal interactive installer.
As mentioned above, the Wireshark installer also installs Npcap. If you prefer to install Npcap manually or want to use a different version than the one included in the Wireshark installer, you can download Npcap from the main Npcap site at https://nmap.org/npcap/.
The official Wireshark Windows package will check for new versions and notify you when they are available. If you have the Check for updates preference disabled or if you run Wireshark in an isolated environment you should subscribe to the wireshark-announce mailing list to be notified of new versions. See Section 1.6.5, “Mailing Lists” for details on subscribing to this list.
New versions of Wireshark are usually released every four to six weeks. Updating Wireshark is done the same way as installing it. Simply download and start the installer exe. A reboot is usually not required and all your personal settings remain unchanged.
Wireshark updates may also include a new version of Npcap. Manual Npcap updates instructions can be found on the Npcap web site at https://nmap.org/npcap/. You may have to reboot your machine after installing a new Npcap version.
You can uninstall Wireshark using the Programs and Features control panel. Select the “Wireshark” entry to start the uninstallation procedure.
The Wireshark uninstaller provides several options for removal. The default is to remove the core components but keep your personal settings and Npcap. Npcap is kept in case other programs need it.