De acordo com a seção SSH do Wireshark Wiki , apenas as partes de texto simples da conexão (para troca de chaves e outras -shaking) estão disponíveis e não é possível descriptografar os pacotes criptografados.
The SSH dissector in Wireshark is functional, dissecting most of the connection setup packets which are not encrypted.
Unlike the SSL dissector, no code has been written to decrypt encrypted SSH packets/payload. This is also not possible unless the shared secret (from the Diffie-Hellman key exchange) is extracted from the SSH server or client (the "SSLKEYLOGFILE" method in SSL).