Skip to content

Instantly share code, notes, and snippets.

Last active Mar 2, 2021
What would you like to do?
Live capture a Chrome or Firefox pcap/ng download as it is downloading
#!/usr/bin/env bash
# This script will detect if there are any new partial download files
# And launch wire/tshark to read them as a live capture.
SHARK_CMD="wireshark -k -i -"
# SHARK_CMD="tshark -r -"
function DL_PARTIALS {
# Partial names: Chrome=$file.crdownload, Firefox=$file.part, Safari=$, Edge=$file.RaNd0mStr.partial
find "$DL_DIR" -maxdepth 1 | perl -ne 'print /(.*pcapng\.(part|crdownload|download|[a-zA-Z0-9]+\.partial))/'
while true; do
while [ "$file" = "" ]; do sleep 1; file="$(DL_PARTIALS)"; done
# Don't reopen wireshark if the user closed it for this file
if [ "$prev_file_id" != "$(stat -c %i $file)" ]; then
echo "Found download partial \`$file\`"
tail -f -n +1 $file | $SHARK_CMD
sleep 1
prev_file_id="$(stat -c %i $file)"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment