This wiki has been migrated to and is now deprecated. Please use that site instead.
Differences between revisions 1 and 2
Revision 1 as of 2008-10-18 22:05:06
Size: 1956
Editor: stemplar
Revision 2 as of 2008-10-25 20:59:10
Size: 1976
Editor: stemplar
Deletions are marked like this. Additions are marked like this.
Line 42: Line 42:
 * Wikipedia
 * DICOM Authorative Reference
 * [1] DICOM Description on [[ |Wikipedia]]
 * [2] DICOM Hompage

Digital Imaging and Communications in Medicine (DICOM)

Wikipedia has a very good high level description about DICOM and the protocol specifications can be found at the DICOM Homepage. This page will focus on wireshark specific topics.


XXX - add a brief description of DICOM history

Protocol dependencies

  • TCP: Typically, DICOM uses TCP as its transport protocol. The well known TCP port for DICOM traffic is 104.

Example traffic

XXX - Add example decoded traffic for this protocol here (as plain text or Wireshark screenshot).


Staring with wireshark 1.1.xx, the DICOM dissector has many new features. is now fully functional. Also add info of additional Wireshark features where appropriate, like special statistics of this protocol.

Preference Settings

(XXX add links to preference settings affecting how DICOM is dissected).

Example capture file

XXX - Add a simple example capture file to the SampleCaptures page and link from here (see below). Keep this file short, it's also a good idea to gzip it to make it even smaller, as Wireshark can open gzipped files automatically.

Display Filter

A complete list of DICOM display filter fields can be found in the display filter reference

  • Show only the DICOM based traffic:

Capture Filter

You cannot directly filter DICOM protocols while capturing. However, if you know the TCP port used (see above), you can filter on that one.

  • Capture only the DICOM traffic over the default port (80):
     tcp port 104


Protocols/dicom (last edited 2010-04-06 21:25:33 by GuyHarris)