All tools

Forensics

tcpdump

CLI packet capture utility.

beginner
Linux
macOS
Scanning
Forensics

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

When

Capturing traffic on remote/headless systems.

How

Filter BPF; write PCAP; analyze later in Wireshark.

Why

Lightweight capture everywhere SSH goes.

Commands & usage

sudo tcpdump -i eth0 -w capture.pcap
sudo tcpdump -i eth0 host 192.168.1.10 and port 80
sudo tcpdump -nni any port 53

Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.

Tags

pcap
cli
network

Related in Forensics