Technology Sharing

Zigbee packet capture based on Wireshark and TiWsPC (Wireshark Packet Converter)

2024-07-06

한어Русский языкEnglishFrançaisIndonesianSanskrit日本語DeutschPortuguêsΕλληνικάespañolItalianoSuomalainenLatina

Preface

Here are some Zigbee packet capture methods:

1. Ubiqua

There are many tutorials online and they are very clear;

But Ubiqua is a paid software and is more expensive;

I tried to install it, but it didn't work after a lot of effort.

2. Killerbee Kit

https://github.com/riverloopsec/killerbee

Attify's integrated killerbee GUI tool:

https://github.com/attify/Attify-Zigbee-Framework

Run installer.sh to install

python main.py start

(I looked this up online, I haven't used it)

3. Wireshark和TiWsPC(Wireshark Packet Converter)

TiWsPC (Wireshark Packet Converter) is combined with the powerful Wireshark to capture Zigbee packets, which is very convenient.

Advantages: Easy to use, free.

Disadvantages: Environment configuration is a bit difficult for novices.

The following introduces the environment configuration and usage of iWsPC combined with the powerful Wireshark for Zigbee packet capture.

Wireshark and TiWsPC preparation

Wireshark and TiWsPC Downloads

Download Zigbee packet capture tool based on Wireshark and TiWsPC (Wireshark Packet Converter)_Download_Sunsili Technology (sunsili.com)

Wireshark and TiWsPC Installation

The installation should be simple for developers. Double-click to install and click Next until it is finished.

Wireshark and TiWsPC packet capture steps

Open TiWsPc and select Device Configuration

Insert the USB dongle, click "Device Configuration", select the channel, click start, if the number of Paackets increases, it means the selected channel is OK.

tiwspc.png

Select the IEEE channel you want to sniff and click Start

If your TiWsPc looks like this, you are ready to set up Wireshark

Wireshark configuration and usage

Create a new desktop shortcut for Wireshark and add the following to the path:-i\.pipetiwspc_data –k