0

I would like to know if it's possible to monitor if any users are using a network sniffer like Wireshark in my corporate network?.

Jonas
  • 101
  • 1

1 Answers1

3

IIRC Wireshark is copying data received by the network interface and working on them. I don't think it's possible to detect usage of Wireshark or other tools like tcpdump on network layer. On OS layer you might can check wether a device is entering promiscuous mode which indicates something is listening at the device.

frlan
  • 563
  • 5
  • 27