Free, hands-on packet capture & network analysis tutorials. Available in English and Chinese (中文).
openpcap.com is a practical, current guide to capturing and analyzing network traffic — built around real packet captures rather than abstract theory.
- Wireshark — display filters, TCP 3-way handshake, retransmission analysis, HTTPS decryption, DNS query analysis, packet loss detection
- tcpdump — 100+ filter cheat sheet, BPF syntax deep dive, command examples
- Protocols — ARP, DNS, HTTP, TCP, UDP, TLS, ICMP, IPv4, Ethernet references
| Resource | Link |
|---|---|
| Site | https://www.openpcap.com |
| 中文站 | https://www.openpcap.com/zh/ |
| Wireshark filter cheat sheet | https://www.openpcap.com/wireshark/filter-cheat-sheet |
| tcpdump cheat sheet | https://www.openpcap.com/tcpdump/cheat-sheet |
The pcap-samples/ directory contains real, anonymized packet captures used in
the tutorials. Open them in Wireshark to follow along hands-on.
Corrections and improvements are welcome — open an issue or pull request. See CONTRIBUTING.md for details.
MIT — see LICENSE.