Stratoshark

Stratoshark Development Team·WiresharkFoundation.Stratoshark

Stratoshark lets you explore and analyze applications at the system call level using a mature, proven interface based on Wireshark.

Stratoshark lets you explore and analyze applications at the system call level using a mature, proven interface based on Wireshark. Stratoshark lets you explore and investigate the application-level behavior of your systems. You can capture system call and log activity and use a variety of advanced features to troubleshoot and analyze that activity.

winget install --id WiresharkFoundation.Stratoshark --exact --source winget

Latest 0.10.3·September 2, 2026

Release Notes

What’s New The following changes have been made since version 0.10.2:

  • The minimum supported Windows version is Windows 10 21H2 (build 19044) or Windows Server 2022.
  • Extcap interfaces now support “bookmarks,” which let you have multiple configurations for the same interfaces. Extcap configurations are now shared across profiles, and existing per-profile configurations will be migrated to bookmarks. Issue 14224.
  • An issue which prevented loading .scap files generated by Falco or the sysdig CLI utility has been fixed. The following changes have been made since version 0.10.1:
  • Timestamps missing in Stratoshark in 0.10.0 and 0.10.1. Issue 21406. The following changes have been made since version 0.10.0: The Stratoshark Windows installer now includes a DLL that was required by the cloudtrail and gcpaudit plugins. The following issues have been fixed: * Wireshark appears in German where Systemlanguage is Dutch. Issue 20347. * If you double-click an interface in the welcome screen interface list, and have typed nothing in the capture filter box, the system reports an invalid capture filter. Issue 21303. * Qt: Appearance mode is stored per-profile while theme name is global — theme flips on profile switch. Issue 21311. * Qt: ‘Recent filters’ arrow button gives no hover/pressed feedback. Issue 21322. * Qt: Hidden interfaces (Welcome page right-click) not persisted across profile switch or restart. Issue 21325. * Qt: Preferences dialog left category tree cannot be resized (labels truncated, only horizontal scrollbar) Issue 21327. * Stratoshark: no-libpcap compilation broken (actionCaptureRestart) — fix from 554baf6294 never applied. Issue 21328. * Qt: Make theme preview resemble a real Wireshark window (mini packet-list mockup) Issue 21329. * stratoshark -D lists a bunch of network capture devices. Issue 21332. The following changes have been made since version 0.9.3:
  • Stratoshark can now read Process Monitor (Procmon) files.
  • Welcome Page Redesign The welcome page has been redesigned to be more informative and easier to navigate. It now highlights the learning sections better and includes a new sidebar with tips and tricks for using Wireshark effectively. The welcome page is now also more accessible, with improved keyboard navigation and screen reader support.
  • Lua Debugger A built-in Lua script debugger has been added. It supports breakpoints, single-stepping, variable inspection, expression evaluation, and stack traces.
  • Themes Stratoshark now uses the same theme system as Wireshark, driving the colors used throughout the GUI from a single theme instead of many individual color preferences. The renamed Appearance › Theme and Font preferences page lets you pick a theme, switch between Light, Dark, and System appearance, set the packet pane font, and preview the result. A built-in default theme ships with Stratoshark, and additional themes can be installed as JSONC (JSON with Comments) files. The previous per-color settings (marked and ignored packets, “Follow Stream” client and server text, display filter validity, and the selected packet) are now provided by the active theme. Personal themes can now be dropped as single .jsonc files into $HOME/.local/lib/stratoshark/themes (Unix) or %APPDATA%\Stratoshark\themes (Windows); the filename becomes the theme’s name in the dropdown. The exact path is shown in the About dialog’s Folders tab. On first launch after the upgrade, Stratoshark checks the Default profile’s preferences for customized values of the removed per-color settings. If any are found, a personal theme named Personal (Migrated) is created automatically in the personal themes directory, the legacy keys are removed from the Default profile’s preferences file, and the theme is activated so the original visual customizations are preserved. The migration runs once: the generated personal.jsonc can be edited, renamed, or deleted by hand at any time. The welcome page section headers (“Open”, “Capture”, “Learn”) and the filter validity tints have been restored to the historical Classic look (Tango sky_blue brand, saturated GTK-era dark green / dark red filter backgrounds).
  • Zooming (View › Zoom In / View › Zoom Out) now scales the whole window, including the capture and display filter fields and other window elements. Previously only the packet list and detail pane text size changed. The new behavior should be much more useful for demos and presentations.
  • The keyboard shortcuts dialog (About Wireshark → Keyboard Shortcuts) has been moved out of of the About dialog to the menu View → Internals → Keyboard Shortcuts and now has a button to print the list of keyboard shortcuts to an HTML file.
  • The application icon has been updated to support Liquid Glass on macOS Tahoe.
  • Stratoshark and strato can now read plain Kubernetes Audit logs and

Installer type: nullsoft

x64—D044EF8ECE8B2CD8E265E577345D6CC656CABEE5C2F1866FEF83F370147DF88B
arm64—3231AC091C53504F7F181A46F7C87A2C73562EB7230F6AB013019E35C68A6F4E

Details

Homepage
https://stratoshark.org/
License
GPL-2.0-or-later
Publisher
Stratoshark Development Team
Support
https://gitlab.com/wireshark/wireshark/-/issues
Copyright
© Gerald Combs and many others

Tags

networkwireshark

Older versions (4)

0.10.2
x64—C802D381CC864C953C92E97ED07E7082E7941256FA9D5796C6C7DD570C582002
arm64—167B0E82D382100C198864E828AB19B53BC953FB2F7F993D55D193B7817BA1CC
0.10.1
x64—3F98A10553ADE3813D44363E672D36EF51E23873FDBE46B90ACB72F4892013C6
arm64—99FC4DA88484BE94EA32DC9B03BE449B98B1912D1343FFD32EFDC8DD8A975036
0.9.3
x64—F1891C194BCCD8E9627860F2501B473723E19643BE3CC3A87891DE8196818210
arm64—6CB132B44B2EF45608C7D48D3AEA93BD4D73C273288D495DEED4A678901D7EE7
0.9.2
x64—8D3BD7AAAE842A4BFA5F525C29821E0E0F55CD52E54F2766EC74C77D7A709BB5
arm64—B1FA144F426C23E1C2A74BC05D31A8D6BEE2BC91095939E96A1A30AB1A4A9B50