Threat Picture
Latest Cybersecurity News

Gerald Combs: How Ethereal Became Wireshark

He needed a packet analyzer he could afford, so he wrote one. A job change later forced a new name for a growing open-source project.
By Charles Joseph · Updated
Share
Share
Copy URL

On July 14, 1998, a network administrator in Kansas City sent an email announcing version 0.2.0 of a program he called Ethereal. It could capture Ethernet frames and let you browse them, and it was free.

Gerald Combs had written it because the graphical protocol analyzers he needed cost real money, while the free tools were command-line only. He figured he'd release it, take a little feedback and move on.

Patches started arriving within days. Twenty-eight years later the tool is called Wireshark, it's on the laptop of nearly every network engineer and security analyst alive, and Combs is still the one shipping the releases.

Gerald Combs at a Glance

  • In late 1997, Combs needed a tool to track down network problems and wanted to learn more about networking, so he started writing one.
  • Ethereal 0.2.0 went public in July 1998. Other developers began contributing protocol dissectors almost immediately, and a community formed around it.
  • In May 2006 he left for CACE Technologies, the company behind WinPcap, but his old employer kept the Ethereal trademark. He renamed the project Wireshark, and every core developer followed.
  • Wireshark 1.0 shipped in 2008, the year of the first SharkFest conference. Riverbed bought CACE in 2010 and became the project's sponsor.
  • In January 2022, Combs joined Sysdig, the company founded by WinPcap's creator Loris Degioanni, which took over sponsorship of Wireshark.
  • On March 1, 2023, the project got a permanent home in the nonprofit Wireshark Foundation. Combs sits on its board as a director and treasurer.
  • In January 2025, he and Degioanni launched Stratoshark, which brings Wireshark's interface to system calls and cloud logs instead of packets.
  • Wireshark 4.6 shipped in October 2025. Combs still maintains the code and keeps releasing new versions.
Sponsored

The Life of Gerald Combs

Combs's Early Years

Gerald Combs comes from Kansas City, where in 1997 he was doing network administration and running into the problem every network person eventually hits: something on the wire was wrong, and he couldn't see it.

Protocol analyzers existed. The good ones, with a graphical interface that let you click through a captured packet layer by layer, were expensive commercial products. The free ones, tcpdump and snoop, dumped text to a terminal and left the decoding to you.

Combs wanted the graphical kind, on the Unix machines he actually used. In late 1997 he started writing it himself, partly to fix his problems and partly, as the project's history puts it, because he wanted to learn more about networking.

Ethereal

The first public release, Ethereal 0.2.0, went out by email on July 14, 1998. Combs later said he expected to release the software, incorporate the little feedback he got and move on to something else.

Instead he got a patch a couple of days later. Then another, and another. Gilbert Ramirez contributed a low-level dissector almost immediately; Guy Harris started sending patches and dissectors in October 1998; Richard Sharpe followed before the year was out.

That pattern defined the project. A protocol analyzer is only as good as the number of protocols it understands, and every network engineer who hit an unsupported protocol had a reason to write a dissector and send it back. Ethereal quickly blossomed into a thriving developer community, and its list of decoded protocols grew into the thousands.

It was free software under the GNU General Public License, which meant nobody could take it away. Nobody, it turned out, except a trademark lawyer.

Sponsored

The Name Problem

In May 2006 Combs took a job at CACE Technologies, a company best known for WinPcap, the packet-capture library that'd made Ethereal work on Windows. CACE had been founded by Loris Degioanni, who wrote WinPcap as a university student in Italy.

There was a catch. Combs's previous employer held the trademark on the name Ethereal, and he had to leave it behind.

The code was free, the name wasn't, and the only reasonable way to keep the project alive was to rename it. Combs chose Wireshark. Every member of the core development team moved to the new name, and Ethereal has had no active development since.

It was almost a fork, except that the entire project came along. For users it was a confusing summer; for the community it was a demonstration that the tool belonged to the people who built it.

Wireshark 1.0 and SharkFest

In 2008, ten years after that first email, Wireshark reached version 1.0, the first release its developers deemed complete. The same year CACE staged the first SharkFest, a conference for Wireshark developers and users that's run every year since.

Riverbed Technology acquired CACE in October 2010 and became the project's primary sponsor, which meant Combs could keep working on Wireshark as his day job. Version 2.0, in 2015, replaced the aging GTK interface with a new one built on Qt.

Combs's philosophy toward the project is a single sentence he repeats at SharkFest: "Wireshark is a tool and a community. My job is to support both."

Sysdig and a Foundation

In January 2022, Combs joined Sysdig, the cloud security company Degioanni had founded after CACE, and Sysdig took over as Wireshark's sponsor. The move reunited the two men who'd steered the project through the rename.

Wireshark 4.0 arrived that October. Then, on March 1, 2023, the project announced it finally had a permanent home: the Wireshark Foundation, a 501(c)(3) nonprofit that hosts SharkFest, funds development and holds the project's assets independent of any one employer. Combs serves on its board as a director and its treasurer, alongside Degioanni.

Marking the 25th anniversary that July, Combs wrote that successive employers had provided the resources for Wireshark and SharkFest, and that the foundation existed so the project could keep growing and serving its community. The advice he closed with was pure Wireshark: "The community has valuable insights to share. Let them do that."

Sponsored

Stratoshark

Packets aren't the only thing worth dissecting. In cloud environments and containers, much of what matters never crosses a network interface at all; it happens in system calls and logs.

On January 22, 2025, Combs and Degioanni introduced Stratoshark, a sibling application that applies Wireshark's three-pane interface and display filters to Linux system calls and cloud activity. "There is nothing more exciting (or nerve-wracking) than sharing something you've created with the world," they wrote, which is a reasonable thing to say the second time too.

Wireshark Today

Wireshark 4.6 shipped on October 8, 2025, and the releases keep coming. In September 2026 the project pushed out fixes for a wave of vulnerabilities it attributed to the recent trend of AI-assisted bug reports, a problem that didn't exist when Combs started and that now lands in his queue like everything else.

He keynoted SharkFest'26 with a talk on the project's progress, problems and plans, and in August 2026 went home to tell a Kansas City security meetup how the city shaped Wireshark. The tool that started as one administrator's fix is still, by his own description, his job.

Gerald Combs: Still Supporting Both

Plenty of open-source projects have a famous founder. Few have one who's still doing the unglamorous work three decades in: triaging bugs, cutting releases, keeping the dissectors building.

Combs's great decision was to let the community own the thing. When the name was taken from him, the community came with him, and when employers changed, he moved the project somewhere no employer could hold it.

Wireshark's users are still benefiting from that approach. The email was 28 years ago. The patches are still arriving.

QUOTE:

"Amateurs hack systems, professionals hack people."