Table of Contents
Overview
tcpdump
is a powerful command-line packet analyzer that allows you to capture and analyze network traffic in real-time.
Key Features
- Live packet capture
- Protocol analysis
- Filter expressions
- File capture/replay
- Detailed packet info
- Multiple output formats
- Interface selection
- Advanced filtering
Installation
Ubuntu (22.04/24.04)
macOS
Basic Usage
Simple Capture
Common Options
Capture Filters
Host Filters
Port Filters
Protocol Filters
Display Filters
Packet Size
TCP Flags
Complex Filters
Protocol Analysis
HTTP Traffic
DNS Analysis
SSL/TLS Traffic
Advanced Features
File Operations
Buffer Management
Time Stamps
Output Options
Packet Count
Best Practices
Capture Guidelines
Quick Reference
Essential Commands
Common Options
Example Scripts
Traffic Monitor
Protocol Analysis
Security Monitoring
Remember:
- Use appropriate capture filters
- Consider storage space
- Monitor system resources
- Rotate capture files
- Handle sensitive data carefully
- Document capture conditions
For detailed information, consult the man pages (man tcpdump
).