Stratoshark

Stratoshark Development Team·WiresharkFoundation.Stratoshark

Stratoshark lets you explore and analyze applications at the system call level using a mature, proven interface based on Wireshark.

Stratoshark lets you explore and analyze applications at the system call level using a mature, proven interface based on Wireshark. Stratoshark lets you explore and investigate the application-level behavior of your systems. You can capture system call and log activity and use a variety of advanced features to troubleshoot and analyze that activity.

winget install --id WiresharkFoundation.Stratoshark --exact --source winget

Latest 0.10.2·July 15, 2026

Release Notes

What’s New The following changes have been made since version 0.10.1:

  • Timestamps missing in Stratoshark in 0.10.0 and 0.10.1. Issue 21406. The following changes have been made since version 0.10.0:
  • The Stratoshark Windows installer now includes a DLL that was required by the cloudtrail and gcpaudit plugins.
  • Wireshark appears in German where Systemlanguage is Dutch. Issue 20347.
  • If you double-click an interface in the welcome screen interface list, and have typed nothing in the capture filter box, the system reports an invalid capture filter. Issue 21303.
  • Qt: Appearance mode is stored per-profile while theme name is global — theme flips on profile switch. Issue 21311.
  • Qt: ‘Recent filters’ arrow button gives no hover/pressed feedback. Issue 21322.
  • Qt: Hidden interfaces (Welcome page right-click) not persisted across profile switch or restart. Issue 21325.
  • Qt: Preferences dialog left category tree cannot be resized (labels truncated, only horizontal scrollbar). Issue 21327.
  • Stratoshark: no‑libpcap compilation broken (actionCaptureRestart) — fix from 554baf6294 never applied. Issue 21328.
  • Qt: Make theme preview resemble a real Wireshark window (mini packet‑list mockup). Issue 21329.
  • stratoshark -D lists a bunch of network capture devices. Issue 21332. The following changes have been made since version 0.9.3:
  • Stratoshark can now read Process Monitor (Procmon) files.
  • Welcome Page Redesign: the welcome page has been redesigned to be more informative and easier to navigate, with a new sidebar, improved keyboard navigation and screen reader support.
  • Lua Debugger: a built‑in Lua script debugger with breakpoints, single‑stepping, variable inspection, expression evaluation, and stack traces.
  • Themes: Stratoshark now uses the same theme system as Wireshark, with Appearance › Theme and Font preferences, Light/Dark/System appearance, and support for JSONC theme files. Personal themes are migrated automatically.
  • Zooming (View › Zoom In / View › Zoom Out) now scales the whole window, including capture and display filter fields.
  • Keyboard shortcuts dialog moved to View → Internals → Keyboard Shortcuts with a print button.
  • Application icon updated to support Liquid Glass on macOS Tahoe.
  • Stratoshark and strato can now read plain Kubernetes Audit logs, Google Cloud Audit logs, and CloudTrail logs.
  • CloudTrail and Google Cloud Audit log plugins translated to Rust on macOS and Windows. Issue 20869. The following changes have been made since version 0.9.2:
  • Windows installers now ship with Qt 6.8.3 (previously 6.8.1).
  • Stratoshark now ships with “strato”, a command line tool similar to tshark.
  • Windows and macOS packages now ship with the gcpaudit and k8saudit plugins.
  • Falco Events dissector adds IP geolocation fields alongside IPv4 and IPv6 address fields. The following changes have been made since version 0.9.1:
  • New “Plots” dialog provides scatter plots; “I/O Graphs” provides histograms.
  • Falco Bridge dissector renamed to Falco Events; “falcoevents” protocol prefix added with “falcobridge” alias for backward compatibility. Issue 20397.
  • Stratoshark can now show field offsets for supported plugins.
  • Cloudtrail log messages can now be viewed as formatted JSON data.
  • System call dissector adds “falcoevents.fd.stream” field for unique file descriptor numbers; “Follow File Descriptor Stream” uses this field. Issue 20538.
  • Universal macOS installers shipped instead of separate Arm64 and Intel packages. Issue 17294. The following changes have been made since version 0.9.0:
  • Application icons have been updated.

Bug Fixes The following bugs have been fixed since version 0.9.3:

  • Interfaces hidden from the welcome page are now remembered across profile switches and restarts. Issue 21325. The following bugs have been fixed since version 0.9.2:
  • .scap file extension wrongly associated with Wireshark. Issue 20583.
  • sshdig should have a snaplen option. Issue 20586. The following bugs have been fixed since version 0.9.1:
  • Stratoshark help message has Wiresharkisms in it. Issue 20229.
  • Stratoshark and editcap could write incorrect block types. Merge request 19238.
  • Stratoshark says I can’t capture on local interfaces. Issue 20494.
  • Stratoshark: Crash While Sorting on evt.buflen column. Issue 20571. The following bugs have been fixed since version 0.9.0:
  • Falco Bridge: Empty frame.protocols field. Issue 20248.
  • Sysdig event and Falco bridge dissection mismatch due to unsupported pcapng block types. Issue 20358.

New and Updated Features Stratoshark can capture system calls locally on Linux and a variety of log sources on Windows, macOS, and Linux.

  • The welcome screen’s capture‑source activity sparklines now keep their history for the whole session, preserving ordering and showing drops as a separate line. Issue 21318.

Removed Features and Support

  • Dumpcap’s TCP@host:port interface has been removed.
  • Building with Qt 5 is no longer supported.

Getting Stratoshark Stratoshark source code and installation packages are available from https://www.stratoshark.org/download.html.

File Locations Stratoshark looks in several different locations for preference files, plugins, and other files. Use Help › About Stratoshark › Folders to find the default locations on your system.

Getting Help Community support is available on Wireshark’s Q&A site and on the wireshark‑users mailing list. Subscription information and archives for all of Wireshark’s mailing lists can be found on the mailing list site. Bugs and feature requests can be reported on the issue tracker. You can learn system call and log analysis and meet Stratoshark’s developers at SharkFest.

How You Can Help The Wireshark Foundation helps as many people as possible understand their systems and networks. You can find out more and donate at wiresharkfoundation.org.

Installer type: nullsoft

x64C802D381CC864C953C92E97ED07E7082E7941256FA9D5796C6C7DD570C582002
arm64167B0E82D382100C198864E828AB19B53BC953FB2F7F993D55D193B7817BA1CC

Details

Homepage
https://stratoshark.org/
License
GPL-2.0-or-later
Publisher
Stratoshark Development Team
Support
https://gitlab.com/wireshark/wireshark/-/issues
Copyright
© Gerald Combs and many others

Tags

networkwireshark

Older versions (3)

0.10.1
x643F98A10553ADE3813D44363E672D36EF51E23873FDBE46B90ACB72F4892013C6
arm6499FC4DA88484BE94EA32DC9B03BE449B98B1912D1343FFD32EFDC8DD8A975036
0.9.3
x64F1891C194BCCD8E9627860F2501B473723E19643BE3CC3A87891DE8196818210
arm646CB132B44B2EF45608C7D48D3AEA93BD4D73C273288D495DEED4A678901D7EE7
0.9.2
x648D3BD7AAAE842A4BFA5F525C29821E0E0F55CD52E54F2766EC74C77D7A709BB5
arm64B1FA144F426C23E1C2A74BC05D31A8D6BEE2BC91095939E96A1A30AB1A4A9B50