Tcpdump

From DWIKI
Revision as of 08:43, 25 March 2026 by Tony (talk | contribs) (FAQ)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Docs

Tools

  • wireshark

FAQ

Look for ping

tcpdump -i enp1s0 icmp

human readable output

tcpdump -lnX

tcpdump filtering

look for host and port

tcpdump -i ens192 host 192.168.101.3 and tcp port 993


show connections to a certain port

tcpdump -i eth0 tcp dst port 80

Try adding interface (-i)


tcpdump: Mask syntax for networks only

To match a subnet use net instead of host