1. 过滤TCP重传包
!(tcp.analysis.retransmission)
2. 过滤TCP解析错误数据包
使用wireshark打开pcap包,通过条件过滤TCP重传,乱序,丢包,重复响应的包,命令如下:
!tcp.analysis.flags && !tcp.analysis.window_update
3. 过滤TCP重传包
!tcp.flags.reset == 1
4. 过滤TCP所有差错包 和重传包,tcp,modbus
!tcp.analysis.flags && !tcp.analysis.window_update and ip.addr==172.17.0.2 and tcp.port==502 and tcp and !tcp.flags.reset == 1