Add Wireshark display filter support
Maintainers usually reply within 1 day
@NghiaTranUIT is already working on this.
Since Aug 30, 2026.
Assessment
This issue has not been assessed yet.
Description
Description
TCP Viewer has a visual filter builder, but many people already know Wireshark display filters and use them every day.
Add a Wireshark mode to the packet filter panel. A user should be able to type or paste a Wireshark display filter and apply it without exporting the capture or opening another app.
The filter should use TCP Viewer's embedded Wireshark engine. This keeps the syntax and packet results close to Wireshark. The app should check the expression before applying it. If it is invalid, show a useful message, highlight the part that needs fixing, and keep the last working result on screen.
The current Builder mode should stay available for people who prefer the visual controls.
What the filter works with
- Protocol names such as
tcp,udp,dns,http,tls,icmp,arp, andipv6. - Protocol fields such as
tcp.port == 443,ip.addr == 192.168.1.10, andhttp.request.method == "GET". - TLS fields, including server names such as
tls.handshake.extensions_server_name. - Logic with
and,or,not, and parentheses. - Text and payload checks with
containsandmatches. - Sets, ranges, field slices, and common Wireshark helper functions supported by the embedded Wireshark version.
- Wireshark columns such as
_ws.col.protocoland_ws.col.info. - Imported
.pcapand.pcapngfiles. - Running and stopped live captures.
- Existing quick filters and source-list selections.
- Saved custom filters and TCP Viewer session files, so the expression can be reused later.
Example
tcp.port == 443 and tls.handshake.extensions_server_name contains "example.com"
This should show HTTPS packets whose TLS server name contains example.com.
Related implementation: #95
- Dominant language
- Swift
- Stars
- 443
- Forks
- 21
- Avg merge
- 10h 42m
- Merged PRs (30d)
- 11
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from ProxymanApp/TCPViewer
-
Diff ViewPossibly taken @NghiaTranUIT claimed this 8 days ago. OpenDONE
ProxymanApp/TCPViewer#124 · 1 assignee ·
Maintainers usually reply within 1 day
-
RAM usage stays high after Clear AllPossibly taken @NghiaTranUIT claimed this 8 days ago. OpenDONE
Difficulty 3/5 1-2 days Newbie friendliness 55/100
ProxymanApp/TCPViewer#122 · 1 assignee ·
Maintainers usually reply within 1 day
-
Improve MCP with new featurePossibly taken @NghiaTranUIT claimed this 25 days ago. OpenDONE
ProxymanApp/TCPViewer#119 · 1 comment · 1 assignee ·
Maintainers usually reply within 1 day
-
Split ViewMay be free again @NghiaTranUIT claimed this 31 days ago, and no pull request is open. OpenDONE
ProxymanApp/TCPViewer#114 · 1 comment · 1 assignee ·
Maintainers usually reply within 1 day
-
Tab BarMay be free again @NghiaTranUIT claimed this 31 days ago, and no pull request is open. OpenDONE
ProxymanApp/TCPViewer#113 · 1 comment · 1 assignee ·
Maintainers usually reply within 1 day
All issues in ProxymanApp/TCPViewer
Similar issues
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
Maintainers usually reply within 1 day
-
area: desktop area: website priority: P2 type: feature
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
appandflow/stim#3411 · 1 comment ·
Maintainers usually reply within 1 day
-
Bug 🐞
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
mozilla-mobile/firefox-ios#36008 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
ashvardanian/NumKong#397 · 1 comment · 1 reaction ·
-
good first issue help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
harf-promo/decaffeinate#21 ·