Wireshark-users: Re: [Wireshark-users] Searching for Hex in a pcap file using tshark

From: Stephen Fisher <steve@xxxxxxxxxxxxxxxxxx>
Date: Wed, 5 Oct 2011 13:10:30 -0600
On Wed, Oct 05, 2011 at 12:00:47PM -0700, Wes wrote:

> Is there an equivalently method of doing an Edit->Find Packet->Hex 
> value in Wireshark with command options in tshark?

> I've tried multiple -R filters, but haven't hit on the right one 
> yet...

Try -R "frame contains xx:xx" (each hex byte is represented by xx and 
you can have more if needed).