how…

Wireshark works by sniffing all packets that pass by the NIC of the computer with Wireshark installed. This is also known as “promiscous mode”. The actual sniffing is done by a special driver – WinPCAP for Windows and libpcap for *nix operatingsystems.
That driver then passes all captured data on to Wireshark. This process is better known as “capturing” traffic.