← All cheat sheets

TCPDUMP

Plain-text reference · 5 KB. Read it, search it (Ctrl-F) or print it.

PURPOSE#

Capture and read network traffic from the command line for monitoring,
incident response and network forensics. Runs on Linux/macOS/BSD; needs
root (or CAP_NET_RAW). The filter language is BPF, shared with Wireshark's
capture filters, Zeek and many IDS.

BASICS#

tcpdump -D                       List capture interfaces
tcpdump -i eth0                  Capture on eth0
tcpdump -i any                   Capture on all interfaces
tcpdump -c 100                   Stop after 100 packets
tcpdump -n                       Do not resolve hostnames (faster, no DNS)
tcpdump -nn                      Do not resolve hosts OR ports
tcpdump -q                       Quiet / shorter output
tcpdump -t                       No timestamp   |   -tttt human-readable time
tcpdump -e                       Show link-layer (MAC) header
tcpdump -X                       Hex + ASCII of packet payload
tcpdump -A                       ASCII payload only (handy for HTTP text)
tcpdump -v / -vv / -vvv          Increasing verbosity (TTL, options, checksums)

WRITE / READ CAPTURE FILES (for later analysis)#

tcpdump -i eth0 -w capture.pcap            Write raw packets to a pcap
tcpdump -i eth0 -w cap-%Y%m%d-%H%M.pcap \
        -G 3600 -C 100 -W 24               Rotate: hourly, 100 MB cap, keep 24
tcpdump -r capture.pcap                    Read a saved capture
tcpdump -r capture.pcap 'port 53'          Read + filter offline
tcpdump -s 0                               Full packet (default on modern tcpdump)
tcpdump -s 96                              Snap length: headers only, small files

Best practice for IR: capture with -w to a rotating pcap and analyse offline;
never rely on terminal scroll-back as evidence.

HOST / NETWORK / PORT FILTERS#

host 10.0.0.5                    To or from that host
src host 10.0.0.5                Source only
dst host 10.0.0.5                Destination only
net 10.0.0.0/24                  Whole subnet
port 443                         Port 443 either direction
src port 1024                    Source port
portrange 8000-8100              Range of ports
ether host aa:bb:cc:dd:ee:ff     Match a MAC address
tcp / udp / icmp / arp           By protocol

COMBINING FILTERS (BPF logic)#

and / && , or / || , not / !
tcpdump 'host 10.0.0.5 and port 443'
tcpdump 'src net 10.0.0.0/24 and not port 22'
tcpdump 'tcp and (port 80 or port 443)'
tcpdump 'icmp and not host 10.0.0.1'
Always single-quote a filter that contains spaces or parentheses.

TCP FLAGS (spot scans, resets, handshakes)#

tcp[tcpflags] & tcp-syn  != 0              Any packet with SYN set
'tcp[tcpflags] == tcp-syn'                 SYN only (connection attempts)
'tcp[tcpflags] & (tcp-syn|tcp-ack) == tcp-syn'   SYN without ACK (half-open)
'tcp[tcpflags] & tcp-rst != 0'             Resets (refused / torn-down)
'tcp[tcpflags] & tcp-fin != 0'             FIN (graceful close / FIN scan)
tcp-syn tcp-ack tcp-fin tcp-rst tcp-push tcp-urg are the named bits.

COMMON DEFENSIVE / IR ONE-LINERS#

# DNS queries and answers (exfil / C2 over DNS, odd lookups)
tcpdump -nn -i any 'udp port 53'

# Cleartext HTTP requests (hosts, user-agents, paths)
tcpdump -nnA -s 0 'tcp port 80 and (tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x47455420)'   # "GET "

# New outbound connections from a server that should not initiate any
tcpdump -nn 'tcp[tcpflags] == tcp-syn and src host 10.0.0.50'

# Traffic to a suspected C2 IP, full payload, to a file
tcpdump -nn -s 0 -w c2.pcap 'host 203.0.113.10'

# ICMP tunnelling / ping sweeps
tcpdump -nn 'icmp'

# ARP anomalies (spoofing, new hosts on the LAN)
tcpdump -nn 'arp'

# Everything to/from one host except your SSH session (avoid feedback loop)
tcpdump -nn 'host 10.0.0.5 and not (host <your-ip> and port 22)'

READING THE OUTPUT#

12:00:01.123456 IP 10.0.0.5.51514 > 93.184.216.34.443: Flags [S], seq 12345, ...
  ^timestamp        ^src.ip.port      ^dst.ip.port   ^flags  [S]=SYN [.]=ACK
  Flags: S=SYN  .=ACK  P=PSH  F=FIN  R=RST  U=URG
Use -tttt for a full date-time, -nn so IPs/ports are not rewritten to names.

SAFETY / GOTCHAS#

- Capturing traffic can expose credentials and personal data: get
  authorisation, limit scope with tight filters, store pcaps encrypted and
  delete them on a retention schedule (GDPR).
- -s 0 on a busy link fills disk fast; use rotation (-G/-C/-W) or a snap length.
- tcpdump on the same host you SSH into will capture your own session; exclude
  it in the filter to avoid noise and loops.
- For deep analysis move the pcap into Wireshark/tshark, Zeek or Arkime.

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.