Forensics
tcpdump
CLI packet capture utility.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Capturing traffic on remote/headless systems.
How
Filter BPF; write PCAP; analyze later in Wireshark.
Why
Lightweight capture everywhere SSH goes.
Commands & usage
sudo tcpdump -i eth0 -w capture.pcap
sudo tcpdump -i eth0 host 192.168.1.10 and port 80
sudo tcpdump -nni any port 53
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Comparisons
Tags
Related in Forensics
Volatility 3
Memory forensics framework for RAM dumps.
Autopsy
GUI digital forensics platform on The Sleuth Kit.
The Sleuth Kit
CLI tools for disk image forensic analysis.
Wireshark / tshark
World-class packet capture and protocol analysis tool.
ExifTool
Read/write metadata in files (images, docs, etc.).
steghide / zsteg / steghide tools
Steganography detection and extraction tools for CTFs and investigations.