When analyzing PCAP files, it’s helpful to know the file’s internal details. This helps you identify, classify, and prioritize files — especially during complex investigations. Details like file hash, capture time, interface used, and comments can give important context.
How to View File Details in Wireshark
You can access the capture file properties using one of two methods:
Option 1: Menu Navigation
Go to:
Statistics → Capture File Properties
Option 2: Quick Icon Access
Click the small PCAP file icon in the bottom-left corner of the Wireshark window.