Null scans use legal TCP packet formats, but listen for illegally-formed TCP response packets.
You have opened a trace file that has been sent to you and you noticed the timestamp only offers millisecond-level time values. You can enable Wireshark to add the microsecond detail information to these packets.
What is the maximum MAC Service Data Unit (MSDU) size defined by the IEEE 802.11 specification?
The gratuitous ARP process is not required if a host is configured with a static IP address.
How do you quickly spot large gaps in time between packets in a trace file containing 6,000 packets?
All packets that contain UDP or TCP headers are counted in the IP Protocol Types statistic.
DNS responses contain four sections: Question, Answer RR, Authority RR and Additional RR.
Wireshark can capture traffic on an interface even if that interface is not listed on the Start Page.

This is a DNS inverse query packet used to resolve an IP address to a host name.
Session Initiation Protocol (SIP) is a protocol that can be used to carry voice data.
To increase the number of recently created display filters that Wireshark remembers, increase the Filter display max, list entries value in Wireshark's Preferences window.
Network analysis is often considered 'electronic surveillance' or 'wiretapping* and may be illegal.
Wireshark contains numerous pre-defined columns that can be added easily to the Packet List pane.
Applications may override the default port value defined in the TCP/IP stack services file.
When you apply a display filter, the Status Bar indicates the total number of packets captured and the packets displayed.
Time reference packets are permanently given a timestamp of 00:00:00. When you close and reopen the trace file the time reference information is retained.