TCPDUMP
PURPOSE#
Capture and read network traffic from the command line for monitoring, incident response and network forensics. Runs on Linux/macOS/BSD; needs root (or CAP_NET_RAW). The filter language is BPF, shared with Wireshark's capture filters, Zeek and many IDS.
BASICS#
tcpdump -D List capture interfaces tcpdump -i eth0 Capture on eth0 tcpdump -i any Capture on all interfaces tcpdump -c 100 Stop after 100 packets tcpdump -n Do not resolve hostnames (faster, no DNS) tcpdump -nn Do not resolve hosts OR ports tcpdump -q Quiet / shorter output tcpdump -t No timestamp | -tttt human-readable time tcpdump -e Show link-layer (MAC) header tcpdump -X Hex + ASCII of packet payload tcpdump -A ASCII payload only (handy for HTTP text) tcpdump -v / -vv / -vvv Increasing verbosity (TTL, options, checksums)
WRITE / READ CAPTURE FILES (for later analysis)#
tcpdump -i eth0 -w capture.pcap Write raw packets to a pcap
tcpdump -i eth0 -w cap-%Y%m%d-%H%M.pcap \
-G 3600 -C 100 -W 24 Rotate: hourly, 100 MB cap, keep 24
tcpdump -r capture.pcap Read a saved capture
tcpdump -r capture.pcap 'port 53' Read + filter offline
tcpdump -s 0 Full packet (default on modern tcpdump)
tcpdump -s 96 Snap length: headers only, small files
Best practice for IR: capture with -w to a rotating pcap and analyse offline;
never rely on terminal scroll-back as evidence.
HOST / NETWORK / PORT FILTERS#
host 10.0.0.5 To or from that host src host 10.0.0.5 Source only dst host 10.0.0.5 Destination only net 10.0.0.0/24 Whole subnet port 443 Port 443 either direction src port 1024 Source port portrange 8000-8100 Range of ports ether host aa:bb:cc:dd:ee:ff Match a MAC address tcp / udp / icmp / arp By protocol
COMBINING FILTERS (BPF logic)#
and / && , or / || , not / ! tcpdump 'host 10.0.0.5 and port 443' tcpdump 'src net 10.0.0.0/24 and not port 22' tcpdump 'tcp and (port 80 or port 443)' tcpdump 'icmp and not host 10.0.0.1' Always single-quote a filter that contains spaces or parentheses.
TCP FLAGS (spot scans, resets, handshakes)#
tcp[tcpflags] & tcp-syn != 0 Any packet with SYN set 'tcp[tcpflags] == tcp-syn' SYN only (connection attempts) 'tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn' SYN without ACK (half-open) 'tcp[tcpflags] & tcp-rst != 0' Resets (refused / torn-down) 'tcp[tcpflags] & tcp-fin != 0' FIN (graceful close / FIN scan) tcp-syn tcp-ack tcp-fin tcp-rst tcp-push tcp-urg are the named bits.
COMMON DEFENSIVE / IR ONE-LINERS#
# DNS queries and answers (exfil / C2 over DNS, odd lookups) tcpdump -nn -i any 'udp port 53' # Cleartext HTTP requests (hosts, user-agents, paths) tcpdump -nnA -s 0 'tcp port 80 and (tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x47455420)' # "GET " # New outbound connections from a server that should not initiate any tcpdump -nn 'tcp[tcpflags] == tcp-syn and src host 10.0.0.50' # Traffic to a suspected C2 IP, full payload, to a file tcpdump -nn -s 0 -w c2.pcap 'host 203.0.113.10' # ICMP tunnelling / ping sweeps tcpdump -nn 'icmp' # ARP anomalies (spoofing, new hosts on the LAN) tcpdump -nn 'arp' # Everything to/from one host except your SSH session (avoid feedback loop) tcpdump -nn 'host 10.0.0.5 and not (host <your-ip> and port 22)'
READING THE OUTPUT#
12:00:01.123456 IP 10.0.0.5.51514 > 93.184.216.34.443: Flags [S], seq 12345, ... ^timestamp ^src.ip.port ^dst.ip.port ^flags [S]=SYN [.]=ACK Flags: S=SYN .=ACK P=PSH F=FIN R=RST U=URG Use -tttt for a full date-time, -nn so IPs/ports are not rewritten to names.
SAFETY / GOTCHAS#
- Capturing traffic can expose credentials and personal data: get authorisation, limit scope with tight filters, store pcaps encrypted and delete them on a retention schedule (GDPR). - -s 0 on a busy link fills disk fast; use rotation (-G/-C/-W) or a snap length. - tcpdump on the same host you SSH into will capture your own session; exclude it in the filter to avoid noise and loops. - For deep analysis move the pcap into Wireshark/tshark, Zeek or Arkime.
TCPDUMP CHEATSHEET
==================
Source: https://cyberramen.com/en/cheatsheets
PURPOSE
-------
Capture and read network traffic from the command line for monitoring,
incident response and network forensics. Runs on Linux/macOS/BSD; needs
root (or CAP_NET_RAW). The filter language is BPF, shared with Wireshark's
capture filters, Zeek and many IDS.
BASICS
------
tcpdump -D List capture interfaces
tcpdump -i eth0 Capture on eth0
tcpdump -i any Capture on all interfaces
tcpdump -c 100 Stop after 100 packets
tcpdump -n Do not resolve hostnames (faster, no DNS)
tcpdump -nn Do not resolve hosts OR ports
tcpdump -q Quiet / shorter output
tcpdump -t No timestamp | -tttt human-readable time
tcpdump -e Show link-layer (MAC) header
tcpdump -X Hex + ASCII of packet payload
tcpdump -A ASCII payload only (handy for HTTP text)
tcpdump -v / -vv / -vvv Increasing verbosity (TTL, options, checksums)
WRITE / READ CAPTURE FILES (for later analysis)
-----------------------------------------------
tcpdump -i eth0 -w capture.pcap Write raw packets to a pcap
tcpdump -i eth0 -w cap-%Y%m%d-%H%M.pcap \
-G 3600 -C 100 -W 24 Rotate: hourly, 100 MB cap, keep 24
tcpdump -r capture.pcap Read a saved capture
tcpdump -r capture.pcap 'port 53' Read + filter offline
tcpdump -s 0 Full packet (default on modern tcpdump)
tcpdump -s 96 Snap length: headers only, small files
Best practice for IR: capture with -w to a rotating pcap and analyse offline;
never rely on terminal scroll-back as evidence.
HOST / NETWORK / PORT FILTERS
-----------------------------
host 10.0.0.5 To or from that host
src host 10.0.0.5 Source only
dst host 10.0.0.5 Destination only
net 10.0.0.0/24 Whole subnet
port 443 Port 443 either direction
src port 1024 Source port
portrange 8000-8100 Range of ports
ether host aa:bb:cc:dd:ee:ff Match a MAC address
tcp / udp / icmp / arp By protocol
COMBINING FILTERS (BPF logic)
-----------------------------
and / && , or / || , not / !
tcpdump 'host 10.0.0.5 and port 443'
tcpdump 'src net 10.0.0.0/24 and not port 22'
tcpdump 'tcp and (port 80 or port 443)'
tcpdump 'icmp and not host 10.0.0.1'
Always single-quote a filter that contains spaces or parentheses.
TCP FLAGS (spot scans, resets, handshakes)
------------------------------------------
tcp[tcpflags] & tcp-syn != 0 Any packet with SYN set
'tcp[tcpflags] == tcp-syn' SYN only (connection attempts)
'tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn' SYN without ACK (half-open)
'tcp[tcpflags] & tcp-rst != 0' Resets (refused / torn-down)
'tcp[tcpflags] & tcp-fin != 0' FIN (graceful close / FIN scan)
tcp-syn tcp-ack tcp-fin tcp-rst tcp-push tcp-urg are the named bits.
COMMON DEFENSIVE / IR ONE-LINERS
--------------------------------
# DNS queries and answers (exfil / C2 over DNS, odd lookups)
tcpdump -nn -i any 'udp port 53'
# Cleartext HTTP requests (hosts, user-agents, paths)
tcpdump -nnA -s 0 'tcp port 80 and (tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x47455420)' # "GET "
# New outbound connections from a server that should not initiate any
tcpdump -nn 'tcp[tcpflags] == tcp-syn and src host 10.0.0.50'
# Traffic to a suspected C2 IP, full payload, to a file
tcpdump -nn -s 0 -w c2.pcap 'host 203.0.113.10'
# ICMP tunnelling / ping sweeps
tcpdump -nn 'icmp'
# ARP anomalies (spoofing, new hosts on the LAN)
tcpdump -nn 'arp'
# Everything to/from one host except your SSH session (avoid feedback loop)
tcpdump -nn 'host 10.0.0.5 and not (host <your-ip> and port 22)'
READING THE OUTPUT
------------------
12:00:01.123456 IP 10.0.0.5.51514 > 93.184.216.34.443: Flags [S], seq 12345, ...
^timestamp ^src.ip.port ^dst.ip.port ^flags [S]=SYN [.]=ACK
Flags: S=SYN .=ACK P=PSH F=FIN R=RST U=URG
Use -tttt for a full date-time, -nn so IPs/ports are not rewritten to names.
SAFETY / GOTCHAS
----------------
- Capturing traffic can expose credentials and personal data: get
authorisation, limit scope with tight filters, store pcaps encrypted and
delete them on a retention schedule (GDPR).
- -s 0 on a busy link fills disk fast; use rotation (-G/-C/-W) or a snap length.
- tcpdump on the same host you SSH into will capture your own session; exclude
it in the filter to avoid noise and loops.
- For deep analysis move the pcap into Wireshark/tshark, Zeek or Arkime.
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.