# Wireshark VRU Awareness Service (VAM) Dissector Extension ## Purpose Wireshark natively dissects IEEE 1609.2 / ETSI TS 103 097 secured packets, but stops dissecting at `Ieee1609Dot2Data.unsecuredData` unless the ITS Application ID (PSID) is registered in Wireshark's internal `ieee1609dot2.psid` dissector table. - Standard PSIDs like CAM (`36`) and DENM (`37`) are registered by default in Wireshark 4.x. - **PSID 638** (VRU Awareness Service, ETSI TS 102 965) is not registered in Wireshark 4.x. This Lua plugin registers **PSID 638** to point to the GeoNetworking common header (`gnw.comm`), allowing Wireshark to continue dissecting the entire stack: ``` IEEE 802.11 (5.9 GHz ITS-G5) -> LLC/SNAP 0x8947 -> GeoNetworking -> BTP-B (port 2018) -> VAM (TS 103 300-3) ``` ## Installation ### Windows Copy `psid-vru.lua` into your personal Wireshark plugins directory: ```powershell Copy-Item tools/wireshark/psid-vru.lua "$env:APPDATA\Wireshark\plugins\" ``` ### Linux Copy `psid-vru.lua` into: ```bash mkdir -p ~/.local/lib/wireshark/plugins cp tools/wireshark/psid-vru.lua ~/.local/lib/wireshark/plugins/ ``` ### macOS Copy `psid-vru.lua` into: ```bash mkdir -p ~/.config/wireshark/plugins cp tools/wireshark/psid-vru.lua ~/.config/wireshark/plugins/ ``` ## Verification 1. Open Wireshark. 2. Navigate to **Help -> About Wireshark -> Plugins**. 3. Verify that `psid-vru.lua` is listed as active. ## Command-Line Usage (tshark) You can directly pass the Lua script to `tshark` without installing: ```bash tshark -X lua_script:tools/wireshark/psid-vru.lua -r capture.pcap ```