4 ms·
Show HN: Babyshark – Wireshark made easy (terminal UI for PCAPs)
Hey all, I built babyshark, a terminal UI for PCAPs aimed at people who find Wireshark powerful but overwhelming.
The goal is “PCAPs for humans”:
Overview dashboard answers what’s happening + what to click next
Domains view (hostnames first) → select a domain → jump straight to relevant flows
(works even when DNS is encrypted/cached by using observed IPs from flows)
Weird stuff view surfaces common failure/latency signals (retransmits/out-of-order hints, resets, handshake issues, DNS failures when visible)
From there you can drill down: Flows → Packets → Explain (plain-English hints) / follow stream
Commands:
Offline: babyshark --pcap capture.pcap
Live (requires tshark): babyshark --list-ifaces then babyshark --live en0
Repo + v0.1.0 release: https://github.com/vignesh07/babyshark https://github.com/vignesh07/babyshark
Would love feedback on UX + what “weird detectors” you’d want next.
- bombcar 7mo agoWHILE DO; DO; DO; DO; DO; DO
- dmbche 7mo ago10/10
- jagermo 7mo agoi finally had that song out of my head.
- fuzzylightbulb 7mo agoI hate that this works
- jetbalsa 7mo agoThis might be a clone of termshark as it does the same thing for the most part. Also to note that the Author's Github profile shows a good bit of vibe coding as of late. Looking over the commit history of this project, I'm about 90% sure it was entirely done with a AI Coding Agent, and not even a very good one.
- eigen-vector 7mo agoThanks for the look. Babyshark is inspired by a bunch of terminal tools (termshark included), but the focus here is different: domains/weirdness-first drilldowns + "explain" + live-mode hostname hints (including observed IPs when DNS is encrypted/cached). If you try it and have specific gaps vs termshark, I'd love concrete feedback /issues.
- gerdesj 7mo agoIt probably is somewhat LLM prompted but is that a bad thing? I have a business partner who sounds like a TV evangelist when it comes to vibe coding but if he gets results then I am all in. He has got quite a lot of results in a few months on a project but he has certainly put the miles in himself. The key is to use the tool appropriately. Don't blindly allow it to do what it likes but guide it all the way using your experience and knowledge. Anyway, we now have tsharkrs to add to gotshark!
- jetbalsa 7mo agoOh Don't get me wrong, I Vibe code the shit of my projects nowadays, but I don't think any of them deserve a Show HN even after I've spent a week polishing them. Claude Code is like crack to my ADHD Programmer brain
- the_biot 7mo agoThe keyword here is "built". I find when people use that, instead of "wrote", it's just AI slop. That only works if there's a sliver of honesty left though.
- jetbalsa 7mo agoI like using put together a program, that sounds just about right for our current AI Overlords
- john_strinlai 7mo agothe overwhelming part of wireshark is, at least in my experience teaching networking at a college level, the actual networking part. protocols, flows, packet structure, etc. kids tend to be up to speed on the UI part pretty quickly. what the kids in my classes really struggle with is actually using any command line stuff (at least for a month or two), because it is so foreign to them (coming from GUI-only experience). what specific parts are made easier with babyshark, compared to wireshark? the github readme didnt really sell me on the "easier than GUI" part, nor did your description here. is it the "explain (plan-English hints)" part? if so, i think you should focus on that. right now it looks pretty bare bones (e.g. "Weird stuff" does not seem easier or super helpful from a learning perspective)
- eigen-vector 7mo agoI'm not trying to say it's better than the GUI but it hopes to be more guided. it’s *opinionated* about the first 60 seconds: - *Overview dashboard*: immediately surfaces top talkers/flows + “what should I click next” instead of dropping you into the full packet list. - *Domains-first pivot*: `D` shows hostnames and lets you jump from a domain → the relevant flows. It also works when DNS answers aren’t visible (DoH/DoT/cached) by using observed IPs from SNI/Host flows. - *Weird stuff*: `W` is a curated set of “likely problems” (retransmits/out-of-order hints, resets, handshake issues, DNS failures when visible) with a short “why it matters” and a drill-down. - *Explain*: `?` gives plain-English hints for a selected flow + suggested next steps (follow stream, filter, pivot to domains/weird). So it’s basically a guided triage layer on top of tshark/pcap data, with the “where do I start?” path baked in. If you’ve got a specific teaching use-case (e.g. “why is this slow?” or “which host is generating traffic?”), I’d love to tune the Overview/Weird detectors around that. Open to PRs as well.
- john_strinlai 7mo ago>So it’s basically a guided triage layer on top of tshark/pcap data, with the “where do I start?” path baked in. i think there is definitely room for something like this, it just (at first glance from the readme at least) seems like the guided part of this tool is bolted on as a bit of an after thought. it feels like you are currently in an odd position where the user is expected to know the networking jargon already, be able to recognize that something might be "weird" at a glance, but also not know how to drill down into the data. i think that is probably a small overlap of people. if i were you, i would lean all-in on making it a learning tool. >If you’ve got a specific teaching use-case (e.g. “why is this slow?” or “which host is generating traffic?”), I’d love to tune the Overview/Weird detectors around that. i will put some thought into some real-world examples of what i would be interested in, from a teaching perspective. your post caught my eye because i am starting my wireshark module next week, so it is certainly timely.
- ghxst 7mo agoHow does it compare against tshark?
- eigen-vector 7mo agoThis isn't meant as a replacement for tshark. It actually uses tshark for the live capture part. tshark is the engine; Babyshark is the guided Ul on top of it. • tshark: raw packet/field dump + powerful filters, but you have to know what fields to ask for and how to stitch the story together. • Babyshark: gives you an opinionated workflow (Overview → Domains/Weird → Flows → Packets/ Stream) with "explain/why it matters" text, curated detectors, and one-key drilldowns. For live capture, Babyshark uses tshark -T fields to extract things like DNS qname / TLS SNI / HTTP host; for offline PCAP it parses enough to build flows + summaries. So: if you already live in tshark one-liners, tshark is faster. If you're trying to understand what's happening or teach/debug quickly, Babyshark is a nicer front-end.
- wonger_ 7mo agoI am in the target audience of "would like to see network activity and debug occasional traffic but totally overwhelmed by termshark." So I appreciate the "what should I click?" thing, and offering weird flows to investigate. --- Some UX bits I noticed after playing around for a few minutes: - Esc for backwards navigation was not obvious for me. Maybe emphasize that somehow, and/or support Backspace too for backnav? - Enter on Domains menu item does not work - don't mention clicking if mouse is not supported. "Select" would be more appropriate - packets screen is truncated vertically and horizontally. Probably should be scrollable - "weird stuff" options are numbered 1-5, but pressing those keys has no effect. There's lots of little polish fixes like this. --- And then things I wonder about as a novice user: - Is it possible to see domain names instead of IP addresses while e.g. looking at packets? - What does it mean to f stream? - How do I inspect packets? Especially compressed or encrypted data? This is more a knowledge gap, like "what am I supposed to look for", "what could be in a packet", and I guess involves reverse engineering sometimes, but it's also a tooling question.
- eigen-vector 7mo agoThanks a lot for trying. My experience with packet inspection is similar and that's what resulted in me trying to build a simpler plain language UI companion. • Back navigation: good call. I'll make "Esc back" more explicit everywhere and add Backspace as an alias for back (and mention it in h help). • Enter on Domains not working: it should drill down to flows. If you can share your OS/terminal + whether you installed from release vs cargo install, I'll try to reproduce and fix in the next release. • "Clicking" wording: agreed — mouse isn't supported right now. I'll change Ul copy to say Select (and keep "Enter = drill down"). • Packets screen truncation: yep, needs scrolling/paging. On the list views I already do r/; l'll add page scroll and horizontal handling where it makes sense. • Numbered weird options: great idea - I'll map 1..9 to jump-select and Enter (or open directly). • Domain names in packets: yes, I want that. I already collect DNS/SNI/HTTP host hints; next step is showing hostname labels alongside IPs when I have more confident mapping. • "f stream" definition: I'll clarify it as "Follow stream (reassembled payload)" and add a glossary/help entry. • Inspecting encrypted/compressed data: totally fair. The tool can't decrypt TLS without keys, but it can make it clearer what's happening (SNI/ ALPN, sizes, timing, resets/retransmits). I'Il improve "Explain" to say what's possible vs not. Super useful feedback thanks!
- denysvitali 7mo agoRegardless of the result of the TUI - I'd try this out just because you found the perfect name. Well done!
- eigen-vector 7mo agothank you :) I would be lying if I said the name wasn't the spark. The project lives to serve the name.
- jedberg 7mo agoAs a parent and a former network engineer, I both love you and hate you for choosing this name.
- eigen-vector 7mo agoSo sorry I couldn't resist :) But hey this is a great way to get your kid interested in networking!
- vardump 7mo agoAt least a two year old. :-) Well, they’re naturally interested in anything daddy does. Especially with the computer!
- eigen-vector 7mo agoSuch a beautiful thing :)
- gerdesj 7mo agoRight: Dear Mr eigen-vector - allow it to be Frozen themed! Ideally add a crappy MIDI style "Let it go" sound track on a loop with a note missing and for perfect torture - shift the notes 1/16 or so of a tone. You can of course do the same with "baby shark" but would anyone notice the changes 8)
- tymscar 7mo agoLove the idea, but please add some demo screenshots on GitHub. All UI tools should
- eigen-vector 7mo agoWill do! I agree
- eigen-vector 7mo agoI've added images to the readme :) Thanks for your feedback!
- protocolture 7mo agoSometimes projects are created and then named, this was named and then created.
- eigen-vector 7mo agoYou are not wrong :)
- badc0ffee 7mo agoWhat's funny is that wireshark/tshark were created (first as "Ethereal") as a "friendlier" tcpdump, with more protocol analyzers.
- nico 7mo agoVery cool, reminds me of sngrep, which I really like for analyzing SIP pcaps
- umairnadeem123 7mo ago[dead]
- eigen-vector 7mo agoThanks a lot! There is a bookmark and export feature that does what you're asking for!
- Bluecobra 7mo agoGreat idea, would it be possible to make it possible to add my own custom tshark one liners under weird stuff? For example, sometimes I find myself troubleshooting TCP retransmission issues that is specific to proprietary applications and that may not be relevant everyone else to have by default. As an aside, I was thinking about something similar to this tool for a while now after seeing this post (https://news.ycombinator.com/item?id=46723990 https://news.ycombinator.com/item?id=46723990) where someone was using Claude to troubleshoot a PCAP. It made me think that it would be nice just to have a nice collection of tshark one-liners to quickly weed out any weird stuff right off the bat. I would assume that it would be a lot more performant than using a LLM and more scalable if you have large PCAP files.
- eigen-vector 7mo agoabsolutely. May be the best way to do this would be some kind of a recipe store where the user can run (we can fuzzy match?) tshark oneliners. I'd love your thoughts on what the easiest/quickest integration would be.
- atoav 7mo agoI know that his has been done at least partially with an LLM because of the wording in the TUI.