How exactly does tshark -z hosts come up with the list?

How exactly does tshark -z hosts come up with the hosts list?

The man page says "Addresses are collected from a number of sources, including standard "hosts" files and captured traffic.".

I am curious to understand what the sources would be. I would assume DNS packets, maybe Windows Netbios or newer Windows protocols?


Just DNS packets, from a quick look at the code; we don't use NBNS traffic to get NetBIOS names.

Thank you, makes sense.

