HomeNewsWireshark 4.6.0 Delivers Scatter Plots, Live Compression, and Ends WinPcap Support

Wireshark 4.6.0 Delivers Scatter Plots, Live Compression, and Ends WinPcap Support

The Wireshark Foundation has released version 4.6.0 of the world’s most popular network protocol analyzer, introducing powerful new visualization tools and officially ending support for the long-obsolete WinPcap driver.

This first release of the 4.6 branch significantly enhances analysis capabilities with a new “Plots” dialog for generating scatter plots, a feature distinct from the existing I/O Graphs histogram tool. Furthermore, the update brings the ability to compress capture files during live packet captures, a major improvement for long-term monitoring sessions.

This version solidifies its modern foundation by mandating Npcap on Windows systems. The installers reflect this shift, bundling Npcap 1.83 and upgrading the UI framework to Qt 6.9.3. For Apple users, Wireshark now ships a universal macOS installer for both Arm64 and Intel hardware, simplifying deployment.

Recommended Post: 25 Best Open Source Security Tools To Protect Your System

Linux users also receive key updates, gaining the ability to use BPF extensions like “inbound” and “ifindex” in capture filters. On the dependency front, support for older libnl versions has been removed, while libxml2 now becomes a required dependency for all builds.

Analysts gain several key enhancements to data handling and decryption. The release adds the ability to decrypt NTP packets using Network Time Security (NTS) and expands MACsec decryption capabilities. In a move toward standardization, absolute timestamps in text-based exports now default to the ISO 8601 UTC format.

Usability improvements are also prominent, including a manual “Redissect Packets” option, an independent light/dark mode, and better integration with tcpdump metadata on macOS.

Recommended Post: 95 Best Linux Monitoring Tools for SysAdmin: An All-in-One List

The update expands its reach with support for new protocols like Binary HTTP and DECT NR+, and new file formats such as RIFF and TTL. The command-line interface, TShark, receives a more flexible -G option for generating glossaries. For developers, the Lua API has been extended with a new Conversation object and support for Libgcrypt symmetric cipher functions.

Wireshark 4.6.0 is available for download from the official website, while most Linux and Unix distributions will provide it through their native package managers.

Mehedi Hasan
Mehedi Hasan
Mehedi Hasan is a dedicated Linux enthusiast with a passion for helping others understand the core concepts of Linux systems. He focuses on breaking down complex topics into simple, beginner-friendly explanations. His goal is to make Linux accessible without overwhelming new learners.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Hot of the Week

Wine 10.17 Arrives with Default EGL Renderer, Mono 10.3.0, and 17 Key Fixes

The Wine development release 10.17 is now available, featuring...

WinBoat 0.8.7 Released with Multi-Monitor Support and Custom Install Paths

The WinBoat project has released version 0.8.7, a significant...

Wine 10.16 Enables NTSYNC for Faster Synchronization on Modern Kernels

The Wine project released version 10.16 on October 3,...

PeaZip 10.7.0 Launches with New File Manager and Image Viewer

PeaZip 10.7.0 refines its file management and viewing experience...

Kdenlive 25.08.1 Released With Major Crash and Rendering Fixes

The Kdenlive project has released version 25.08.1, the first...

> The Latest News