Repository navigation
Packages Tcpdump
Command-line packet capture — the tool that works when nothing else does
- Version recorded: 4.99.5
-
Categories:
capture-analysis,workstation - Upstream: https://www.tcpdump.org/
Captures network traffic from an interface and prints or saves it, with a filter language for selecting what to record.
It is present on everything, needs no display, and its capture files are read by every other tool including Wireshark. On a headless field machine or over a slow SSH link it is the only practical option.
Root, or the CAP_NET_RAW capability, to open an interface for capture.
- apt:
tcpdump
Capturing to a terminal on a busy interface produces more output than anyone can read; -w to a file and analyse afterwards. Its filter syntax is not Wireshark's display-filter syntax, which catches people out constantly.
- probe: apt policy
- strategy: apt_upgrade
Source: catalog/packages/tcpdump.yaml
Generated from docs/ at commit 87965522e214. Canonical site: https://renegade-penguin.github.io/Hammunition/. Edit docs/ by pull request, not this wiki.
- Home
- Software by activity
- Activity hubs
- Installation
- Profiles
-
Guides
- Operating
- Modes
- Receiving
- In the field
- Troubleshooting
- Getting started
- Packages
-
Hardware
- Park and wake devices
- SDR receivers and transceivers
- Radios, GPS and mesh
- Security and research hardware
- Programmers
- Laptop radios and camera (parkable)
- LibreVNA (vector network analyser)
- RF security
-
Reference
- The engine
- Coverage
- Inventories
- Hardware measurements
- Verification
- Contributing