2014-03-01 01:25:34 -03:00
|
|
|
# tcpdump
|
|
|
|
|
2016-01-07 18:31:27 +01:00
|
|
|
> Dump traffic on a network.
|
2019-06-03 02:06:36 +02:00
|
|
|
> More information: <https://www.tcpdump.org>.
|
2014-03-01 01:25:34 -03:00
|
|
|
|
2017-12-03 08:22:45 -08:00
|
|
|
- List available network interfaces:
|
|
|
|
|
2025-03-13 04:41:47 +02:00
|
|
|
`tcpdump {{[-D|--list-interfaces]}}`
|
2017-12-03 08:22:45 -08:00
|
|
|
|
2016-01-07 18:31:27 +01:00
|
|
|
- Capture the traffic of a specific interface:
|
2014-03-01 01:25:34 -03:00
|
|
|
|
2025-03-13 04:41:47 +02:00
|
|
|
`sudo tcpdump {{[-i|--interface]}} {{eth0}}`
|
2014-03-01 01:25:34 -03:00
|
|
|
|
2016-01-07 18:31:27 +01:00
|
|
|
- Capture all TCP traffic showing contents (ASCII) in console:
|
2014-03-01 01:25:34 -03:00
|
|
|
|
|
|
|
`tcpdump -A tcp`
|
|
|
|
|
2016-01-07 18:31:27 +01:00
|
|
|
- Capture the traffic from or to a host:
|
2014-03-01 01:25:34 -03:00
|
|
|
|
2014-03-02 18:20:23 +11:00
|
|
|
`tcpdump host {{www.example.com}}`
|
2014-03-01 01:25:34 -03:00
|
|
|
|
2016-01-07 18:31:27 +01:00
|
|
|
- Capture the traffic from a specific interface, source, destination and destination port:
|
2014-03-01 01:25:34 -03:00
|
|
|
|
2025-03-19 00:36:34 +02:00
|
|
|
`sudo tcpdump {{[-i|--interface]} {{eth0}} src {{192.168.1.1}} and dst {{192.168.1.2}} and dst port {{80}}`
|
2014-03-01 01:25:34 -03:00
|
|
|
|
2016-01-07 18:31:27 +01:00
|
|
|
- Capture the traffic of a network:
|
2014-03-01 01:25:34 -03:00
|
|
|
|
|
|
|
`tcpdump net {{192.168.1.0/24}}`
|
|
|
|
|
2016-01-07 18:31:27 +01:00
|
|
|
- Capture all traffic except traffic over port 22 and save to a dump file:
|
2014-03-27 14:46:32 -04:00
|
|
|
|
2020-09-22 10:09:44 -07:00
|
|
|
`tcpdump -w {{dumpfile.pcap}} port not {{22}}`
|
2017-12-03 08:22:45 -08:00
|
|
|
|
2017-12-04 13:43:33 -08:00
|
|
|
- Read from a given dump file:
|
2017-12-03 08:22:45 -08:00
|
|
|
|
2017-12-04 13:43:33 -08:00
|
|
|
`tcpdump -r {{dumpfile.pcap}}`
|