Hi, How to determine the presence of wireshark in a network ? Are there any specific packet types exchanged while it is present in the network so that it can be used to determine its presence in the network ? Any specific tool to identify its presence in either Windows or Linux ? Any ideas ? Thx in advans, Karthik Balaguru