tcpdump: Network Packet Analyzer

tcpdump is a powerful command-line packet analyzer tool for Unix-like operating systems. It allows you to intercept and display TCP/IP and other network packets being transmitted or received over a network to which the computer is attached. tcpdump is an essential tool for network troubleshooting, security analysis, and understanding network traffic patterns.

1. Interface Selection

List Available Interfaces

To see a list of network interfaces that tcpdump can listen on:

tcpdump -D

Listen on a Specific Interface

To capture traffic on a particular network interface. If no interface is specified, tcpdump usually listens on the first interface it finds.

sudo tcpdump -i <interface_name>
# Example:
sudo tcpdump -i eth0

2. Output Control

Output in ASCII

Displays the packet content in ASCII format, which can be useful for viewing HTTP requests, responses, or other human-readable data.

sudo tcpdump -i <interface_name> -A
# Example: Output ASCII content on eth0
sudo tcpdump -i eth0 -A

Disable Name Resolution (-n, -nn)

By default, tcpdump attempts to resolve IP addresses to hostnames and port numbers to service names. This can slow down output and sometimes be undesirable.

  • -n: Do not convert addresses (e.g., host addresses) to names.
  • -nn: Do not convert protocol and port numbers to names.
# Disable domain resolution
sudo tcpdump -i <interface_name> -n
 
# Disable both domain and port resolution
sudo tcpdump -i <interface_name> -nn

3. Filtering Traffic

tcpdump allows you to filter the traffic it captures using powerful filter expressions.

Filter by Host

Capture traffic to or from a specific host.

# Capture traffic to or from 192.168.1.1
sudo tcpdump -i <interface_name> host 192.168.1.1

Filter by Port

Capture traffic on a specific port.

# Capture traffic on port 80 (HTTP)
sudo tcpdump -i <interface_name> port 80

Filter by Protocol

Capture traffic for a specific protocol (e.g., tcp, udp, icmp).

# Capture only ICMP traffic
sudo tcpdump -i <interface_name> icmp

Combine Filters

Filters can be combined using logical operators (and, or, not).

# Capture TCP traffic to host 192.168.1.1 on port 22
sudo tcpdump -i <interface_name> tcp and host 192.168.1.1 and port 22

4. Saving Captures to a File

It’s common to save captured traffic to a file for later analysis with tools like Wireshark.

sudo tcpdump -i <interface_name> -w <filename.pcap>
# Example:
sudo tcpdump -i eth0 -w capture.pcap
  • -w <filename.pcap>: Writes the raw packet data to the specified file. The .pcap extension is standard.

5. Reading from a Capture File

You can also read and analyze previously saved .pcap files using tcpdump.

tcpdump -r <filename.pcap>
# Example:
tcpdump -r capture.pcap -n port 80
  • -r <filename.pcap>: Reads packets from the specified capture file.

Disclaimer: tcpdump captures raw network traffic, which may contain sensitive information. Only use tcpdump on networks and devices for which you have explicit permission. Unauthorized packet sniffing is illegal and unethical. Ensure compliance with all applicable privacy laws and regulations.