February 23, 2021

How to Decrypt TLS Traffic in Wireshark Using Session Keys (Chris Greer)

TLS Decryption in Wireshark (Chris Greer)

Chris Greer’s walkthrough on decrypting HTTPS traffic in Wireshark is one of those rare tutorials that makes a pretty intimidating topic feel surprisingly doable. He breaks down how TLS 1.3 session keys work, why you normally can’t peek inside encrypted packets, and how a simple environment variable on Windows lets you capture those keys right from your browser. It’s approachable, but still nerdy enough to scratch that packet‑analysis itch.

The core trick is setting the SSLKEYLOGFILE environment variable so Chrome writes out the session keys as it negotiates TLS. Once you’ve got that log file, Wireshark can use it to decrypt the encrypted streams in real time. Chris walks through the exact steps—Control Panel, Advanced System Settings, Environment Variables—and shows how to plug the keylog into Wireshark’s TLS preferences. If you’ve ever wanted to see what’s actually happening inside HTTPS without guessing, this is the cleanest path in.

What makes the video especially useful is how practical it is. Chris doesn’t just explain the concept; he gives you a downloadable trace file and keylog so you can follow along instantly. He also touches on real‑world quirks, like needing to restart Chrome or even reboot Windows depending on your setup. It’s the kind of hands‑on demo that helps you understand not just the “how,” but the “why” behind TLS decryption.

If you’re into network analysis, security research, or just want to level up your Wireshark skills, this video is absolutely worth your time. It’s clear, friendly, and packed with actionable steps. And if you enjoy it, Chris has a whole lineup of deeper courses—from Wireshark certification to Nmap fundamentals—that build on exactly this kind of practical, real‑world troubleshooting. Definitely a solid watch for anyone curious about TLS 1.3, Wireshark, or encrypted traffic analysis.

So how does Chris capture the TLS session keys, feed them to Wireshark and decrypt traffic? In this video he will talk about how to do it. Be sure to download the packet capture and keylog files here so you can follow along.



#netscout Solving Network Blind Spots Created by Massive Data Silos

Solving Network Blind Spots Created by Massive Data Silos


Popular post in the past 30 days