Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

If you right-click on the protocol in the packet details pane, you can choose Copy -> ...as Hex Dump" or "Copy -> ...as Hex Stream". This will allow you to get the hex data for a particular packet.

If, on the other hand, you want the hex data for all packets, then maybe tshark -qx -r file.pcap might be of use, although that will give you the hex data for all layers of the packet and not the hex data for any one protocol of the packet.