What’s New
The following changes have been made since version 0.10.1:
- Timestamps missing in Stratoshark in 0.10.0 and 0.10.1. Issue 21406.
The following changes have been made since version 0.10.0:
- The Stratoshark Windows installer now includes a DLL that was required by the cloudtrail and gcpaudit plugins.
- Wireshark appears in German where Systemlanguage is Dutch. Issue 20347.
- If you double-click an interface in the welcome screen interface list, and have typed nothing in the capture filter box, the system reports an invalid capture filter. Issue 21303.
- Qt: Appearance mode is stored per-profile while theme name is global — theme flips on profile switch. Issue 21311.
- Qt: ‘Recent filters’ arrow button gives no hover/pressed feedback. Issue 21322.
- Qt: Hidden interfaces (Welcome page right-click) not persisted across profile switch or restart. Issue 21325.
- Qt: Preferences dialog left category tree cannot be resized (labels truncated, only horizontal scrollbar). Issue 21327.
- Stratoshark: no‑libpcap compilation broken (actionCaptureRestart) — fix from 554baf6294 never applied. Issue 21328.
- Qt: Make theme preview resemble a real Wireshark window (mini packet‑list mockup). Issue 21329.
- stratoshark -D lists a bunch of network capture devices. Issue 21332.
The following changes have been made since version 0.9.3:
- Stratoshark can now read Process Monitor (Procmon) files.
- Welcome Page Redesign: the welcome page has been redesigned to be more informative and easier to navigate, with a new sidebar, improved keyboard navigation and screen reader support.
- Lua Debugger: a built‑in Lua script debugger with breakpoints, single‑stepping, variable inspection, expression evaluation, and stack traces.
- Themes: Stratoshark now uses the same theme system as Wireshark, with Appearance › Theme and Font preferences, Light/Dark/System appearance, and support for JSONC theme files. Personal themes are migrated automatically.
- Zooming (View › Zoom In / View › Zoom Out) now scales the whole window, including capture and display filter fields.
- Keyboard shortcuts dialog moved to View → Internals → Keyboard Shortcuts with a print button.
- Application icon updated to support Liquid Glass on macOS Tahoe.
- Stratoshark and strato can now read plain Kubernetes Audit logs, Google Cloud Audit logs, and CloudTrail logs.
- CloudTrail and Google Cloud Audit log plugins translated to Rust on macOS and Windows. Issue 20869.
The following changes have been made since version 0.9.2:
- Windows installers now ship with Qt 6.8.3 (previously 6.8.1).
- Stratoshark now ships with “strato”, a command line tool similar to tshark.
- Windows and macOS packages now ship with the gcpaudit and k8saudit plugins.
- Falco Events dissector adds IP geolocation fields alongside IPv4 and IPv6 address fields.
The following changes have been made since version 0.9.1:
- New “Plots” dialog provides scatter plots; “I/O Graphs” provides histograms.
- Falco Bridge dissector renamed to Falco Events; “falcoevents” protocol prefix added with “falcobridge” alias for backward compatibility. Issue 20397.
- Stratoshark can now show field offsets for supported plugins.
- Cloudtrail log messages can now be viewed as formatted JSON data.
- System call dissector adds “falcoevents.fd.stream” field for unique file descriptor numbers; “Follow File Descriptor Stream” uses this field. Issue 20538.
- Universal macOS installers shipped instead of separate Arm64 and Intel packages. Issue 17294.
The following changes have been made since version 0.9.0:
- Application icons have been updated.
Bug Fixes
The following bugs have been fixed since version 0.9.3:
- Interfaces hidden from the welcome page are now remembered across profile switches and restarts. Issue 21325.
The following bugs have been fixed since version 0.9.2:
- .scap file extension wrongly associated with Wireshark. Issue 20583.
- sshdig should have a snaplen option. Issue 20586.
The following bugs have been fixed since version 0.9.1:
- Stratoshark help message has Wiresharkisms in it. Issue 20229.
- Stratoshark and editcap could write incorrect block types. Merge request 19238.
- Stratoshark says I can’t capture on local interfaces. Issue 20494.
- Stratoshark: Crash While Sorting on evt.buflen column. Issue 20571.
The following bugs have been fixed since version 0.9.0:
- Falco Bridge: Empty frame.protocols field. Issue 20248.
- Sysdig event and Falco bridge dissection mismatch due to unsupported pcapng block types. Issue 20358.
New and Updated Features
Stratoshark can capture system calls locally on Linux and a variety of log sources on Windows, macOS, and Linux.
- The welcome screen’s capture‑source activity sparklines now keep their history for the whole session, preserving ordering and showing drops as a separate line. Issue 21318.
Removed Features and Support
- Dumpcap’s TCP@host:port interface has been removed.
- Building with Qt 5 is no longer supported.
Getting Stratoshark
Stratoshark source code and installation packages are available from https://www.stratoshark.org/download.html.
File Locations
Stratoshark looks in several different locations for preference files, plugins, and other files. Use Help › About Stratoshark › Folders to find the default locations on your system.
Getting Help
Community support is available on Wireshark’s Q&A site and on the wireshark‑users mailing list. Subscription information and archives for all of Wireshark’s mailing lists can be found on the mailing list site. Bugs and feature requests can be reported on the issue tracker. You can learn system call and log analysis and meet Stratoshark’s developers at SharkFest.
How You Can Help
The Wireshark Foundation helps as many people as possible understand their systems and networks. You can find out more and donate at wiresharkfoundation.org.