# Wireshark
Wireshark is a technology or product recorded in [[Scanned_20260730-1706|Scanned_20260730-1706]]. In the reconstruction, Wireshark captures and analyzes network packets.
## Historical and Technical Context
[[PXELINUX|PXELINUX]] is the PXE-capable member of the SYSLINUX bootloader family. [[ConnMan|ConnMan]] and [[NetworkManager|NetworkManager]] are competing Linux connection managers. [[ZFS|ZFS]], [[Filesystem in Userspace|FUSE]], `ntfs-3g`, `squashfuse`, and `fuseiso` collectively allow Linux to access diverse filesystems and images. [[Wireshark|Wireshark]] captures and analyzes network packets. [[USBGuard|USBGuard]] enforces USB-device authorization policy; [[ufkill|rfkill/ufkill]] relates to radio-device control; [[Gufw|Gufw]] is a graphical firewall front end; [[linssid|LinSSID]] visualizes Wi-Fi networks. Several package spellings are uncertain and should not be silently normalized.
## Role in Scanned_20260730-1706
This is the notebook's clearest **portable recovery-OS architecture**: boot locally or by PXE; mount nearly any filesystem; acquire network evidence; administer printing and connectivity; and restrict removable-device access.
## Notebook Evidence
- [[Scanned_20260730-1706|Scanned_20260730-1706]], PDF page 15: Boot, filesystem, forensic, and authentication stack.
**Evidentiary status:** The page occurrence and transcription are notebook evidence. Technical identification follows the source reconstruction’s cited research. Co-occurrence does not by itself prove ownership, deployment, or a direct operational relationship.
## Relationships and Overlays
On the cited page or pages, Wireshark appears with [[ConnMan|ConnMan]], [[Filesystem in Userspace|FUSE]], [[Gufw|Gufw]], [[linssid|linssid]], [[NetworkManager|NetworkManager]], [[PXELINUX|PXELINUX]], [[ufkill|ufkill]], [[USBGuard|USBGuard]], [[ZFS|ZFS]]. These are page-level or reconstruction-level relationships, not automatic claims of dependency.
## Cross-Notebook Significance
This note supplies a concrete network-policy or evidence mechanism beneath the AIOps, security-operations, and governance concerns in [[Scanned_20260730-1802|Scanned_20260730-1802]]. It shows how dynamic state is created, observed, and retained at the protocol boundary.
## Missed Signals and Open Leads
Resolve `xdemorse`, `zsys`, `iodine-gui`, `wwnn-sump`, `lms`, `netsniff`, and `usb3dmux` against the actual package manifest if one survives.
## Sources
- [[Scanned_20260730-1706|Scanned_20260730-1706]], especially PDF page(s) 15.
- `Scanned_20260730-1706.pdf`, cited as a plain archival filename; the PDF is not linked from `wiki-notes`.
- External research citations used for identification remain preserved in the source reconstruction.
## Scanned_20260730-1314 overlay
[[Scanned_20260730-1314#Scanned_20260730-1314.pdf — PDF page 56|Pages 56]]: Wireshark appears on the rear cover beside root-shell and AOKP terms, distilling the notebook’s packet-inspection and Android-system themes.
**Relationship overlay:** [[Android Open Kang Project]] · [[Secure Shell]].