Opens in a new tab
vmblog logo 2024 wht (updated)

Sysdig Unveils Stratoshark, Enabling Millions of Network Professionals to Bring Their Security Experience to the Cloud

Share: 

David Marshall | Published: January 22, 2025

Sysdig announced the release of Stratoshark,
an open source tool that extends Wireshark’s granular network
visibility into the cloud and empowers users with a standardized
approach to cloud observability. For 27 years, Wireshark
– with over 5 million daily users and more than 160 million downloads
in the last decade alone – has helped users analyze network traffic and
troubleshoot issues. As companies have transitioned to the cloud,
however, engineers and analysts have lacked the same visibility from a
comparable open source tool. Stratoshark unlocks deep cloud
observability and introspection, helping analyze and troubleshoot cloud
system calls and logs with a level of granularity and workflow familiar
to long-time Wireshark users.

With the growing transition, cloud security is facing a major skills
gap. Considered one of the fastest-growing areas for digital
transformation, there is a shortage of nearly 5 million qualified
cybersecurity professionals, and nearly 40% of respondents in
O’Reilly’s report, “The State of Security in 2024,” noted that cloud
computing is a domain in which more skills are needed but increasingly
difficult to find. By combining Wireshark’s functionality with deep
operational insight from open source Falco
– the standard for cloud-native threat detection, with over 130 million
downloads – Stratoshark unlocks rich cloud context and helps network
analysts and administrators port their experience directly into the
cloud.

“Wireshark revolutionized network analysis by democratizing packet
captures, a concept that Sysdig brought to cloud-native workloads and
Falco extended to cloud runtime security,” said Gerald Combs,
Stratoshark and Wireshark co-creator, Sysdig Director of Open Source
Projects. “Wireshark users live by the phrase ?pcap or it didn’t
happen,’ but until now cloud packet capture hasn’t been easy or even
possible. Stratoshark helps unlock this level of visibility, equipping
network professionals with a familiar tool that makes system call and
log analysis as accessible and transformative for the cloud as Wireshark
did for network packet analysis.”

Continuing a Legacy of Innovation

As organizations have shifted to the cloud, where workloads are more
distributed, dynamic, and short-lived than their traditional
counterparts, visibility into system-level activities has become
increasingly fragmented. Stratoshark seamlessly bridges the gap between
network packet analysis and modern cloud-native security, delivering an
open source solution with broad observability, enhanced extensibility,
and greater developer accessibility.

In essence, Wireshark was developed to support monitoring and security
for traditional on-premises networks, and many experienced network
professionals have long sought a modern application for their expertise.
Stratoshark leverages Falco libraries, repositories, and plug-ins, and
unites its deep cloud visibility with familiar Wireshark functionality.
Stratoshark represents the next generation in a lineage of open source
tools that have set the security standard, simplifying complex
investigations, accelerating incident response, and enabling network
experts to bring their skills to the cloud.

“With Stratoshark, we’re bringing the proven principles of Wireshark to
the complexities of modern environments,” said Loris Degioanni, Sysdig
Founder and CTO; Stratoshark and Wireshark co-creator; and Falco
creator. “By combining Wireshark’s rich network insights with Falco’s
real-time cloud-native security, Stratoshark equips teams to better
understand cloud events, logs, and system calls with open source
accessibility.”