Stratoshark

2 min read Original article ↗

What's really happening in your cloud?

Stratoshark lets you explore and analyze applications at the system call level using a mature, proven interface based on Wireshark. Created for the community by Sysdig.

Download

The latest release of Stratoshark is 0.9.3. You can get it at the following locations: Read all release notes

Learn

Stratoshark lets you explore and investigate the application-level behavior of your systems. You can capture system call and log activity and use a variety of advanced features to troubleshoot and analyze that activity. If you've ever used Wireshark, Stratoshark will look very familiar! It's a sibling application that shares the same dissection and filtering engine and much of the same user interface. It supports the same file format as Falco and Sysdig CLI, which lets you pivot seamlessly between each tool. As an added bonus, it's open source, just like Wireshark and Falco.

Quick start guide

Stratoshark wiki page

Getting Started With Stratoshark, blog post by Josh Clark

Stratoshark remote capture tutorial, blog post by Philippe Bogaerts

Videos

Stratoshark demo from Sysdig
Open Source Summit 2025: Bring the Power of Wireshark To Syscalls and Logs With Stratoshark by Gerald Combs

Stratoshark Tutorial: Getting Started with Gerald Combs by Chris Greer

Stratoshark demo by Ross Bagurdes

Get Help

Wireshark Q&A community