← All 79 books tcpdump, one move per page Get the full edition · £10
One move per page

tcpdump, one move per page

Thirty moves for the person who ssh'd into a box because the network is slow: -D to find the wire, -c to stop cleanly, -n to skip the name lookups, host, src, port and net to sieve the traffic, tcp[tcpflags] to see handshakes and resets, -w to save the raw pcap and -r to read it back, -G, -C and -W to rotate the files before they fill the disk, -A and -X to look inside a payload, and the exit tally that tells you when you dropped packets without knowing.


Steve Hodgkiss 7 moves

A diagram, the command, and one thing to go run this week. That's a page.

tcpdump, one move per page

Thirty moves for the person who ssh'd into a box because the network is slow: -D to find the wire, -c to stop cleanly, -n to skip the name lookups, host, src, port and net to sieve the traffic, tcp[tcpflags] to see handshakes and resets, -w to save the raw pcap and -r to read it back, -G, -C and -W to rotate the files before they fill the disk, -A and -X to look inside a payload, and the exit tally that tells you when you dropped packets without knowing.


Set in Space Grotesk, Inter and JetBrains Mono (SIL Open Font License).

Every flag, filter, default and number in this book is as the official sources state it, fetched and read during this build: the tcpdump(1) man page, version 4.99.5, and the pcap-filter(7) man page (tcpdump.org, The Tcpdump Group). Demand evidence from live beginner searches and cheat-sheet popularity, fetched this build; no facts are sourced from cheat sheets or Reddit. Teaching conventions (one move a page) are named as conventions. Capturing traffic on networks you do not own may require permission and may be restricted by law.

General information only. Not professional advice; check flags against your own tcpdump version, which may differ.

© 2026 Steve Hodgkiss. All rights reserved. Personal use only; no redistribution rights.

Edition 1.0 · stevehodgkiss.net

Contents

Contents


Part 1 · Start4
What tcpdump is5
Find your interface6
Count and stop7
Part 2 · Read the line
Reading a TCP line8
Part 3 · Filter language
host9
Part 4 · Save and rotate
Write a pcap10
Part 5 · Habit
One habit11
Part 1 of 5
the tool, the wire, the stop
1

Start

What tcpdump prints, how to name the interface you mean, and how to make a capture stop itself.


In this part
  1. 01What tcpdump is
  2. 02Find your interface
  3. 03Count and stop

Per the tcpdump(1) man page (tcpdump.org, tcpdump 4.99.5), DESCRIPTION: tcpdump prints out a description of the contents of packets on a network interface that match the Boolean expression; the description is preceded by a time stamp, printed by default as hours, minutes, seconds, and fractions of a second since midnight; it can also be run with the -w flag, which causes it to save the packet data to a file for later analysis, and/or with the -r flag, which causes it to read from a saved packet file rather than to read packets from a network interface; in all cases, only packets that match the expression will be processed by tcpdump.

packet capture · No. 01
Start

What tcpdump is

It prints packets, that's all

PRINT NOW, OR SAVE FOR LATERpackets on the wirethe filter14:03:22.419203 IP web.https > 10.0.0.9.ssh: Flags [S]one line per packet, time stamped-w-rsave raw, read backonly matches processeda description of packets that match a Boolean expression, that's the whole tool

Tcpdump prints a description of the contents of packets on a network interface that match the Boolean expression. Each line is preceded by a time stamp: hours, minutes, seconds and fractions of a second since midnight.

Two directions, later. -w saves the raw packet data to a file for later analysis; -r reads from a saved file instead of an interface. In all cases, only packets matching the expression are processed.

Print now, or save for later. Every page in this book does one of the two.

RUN THIS WEEK

Run tcpdump on any box you're allowed to, watch three lines scroll past, then stop it with control-C.

Per the tcpdump(1) man page (tcpdump.org, tcpdump 4.99.5), OPTIONS: -D / --list-interfaces prints the list of the network interfaces available on the system and on which tcpdump can capture packets, for each interface a number and an interface name, possibly followed by a text description; -i interface / --interface= listens on that interface; if unspecified, tcpdump searches the system interface list for the lowest numbered, configured up interface (excluding loopback), which may turn out to be eth0; on Linux systems with 2.2 or later kernels, and on recent macOS and Solaris, an interface argument of any can be used to capture packets from all interfaces; note that captures on the any pseudo-interface will not be done in promiscuous mode; an interface number as printed by -D can be used as the -i argument.

packet capture · No. 02
Start

Find your interface

Pick the wire you listen on

NAME THE WIRE BEFORE YOU LISTEN$ tcpdump -D1.eth02.wlan03.any4.lo[up, connected][pseudo: allinterfaces]-i eth0any = all of thembut never promiscuousbare tcpdump guesses the lowest numbered up interface, excluding loopback

Before anything, name the wire. tcpdump -D lists every interface it can capture on, each with a number, a name, maybe a description. That number works as the -i argument too.

Run bare tcpdump and it picks for you: the lowest numbered, configured up interface, excluding loopback, which the man page says may turn out to be eth0. Linux, recent macOS and Solaris also accept any, all interfaces at once, with one caveat: captures on any are not promiscuous.

-D once, -i forever. Don't let the tool guess the wire.

RUN THIS WEEK

Run tcpdump -D today and write down which interface carries your traffic. Every later command names it.

Per the tcpdump(1) man page (tcpdump.org, tcpdump 4.99.5), DESCRIPTION: tcpdump will, if not run with the -c flag, continue capturing packets until it is interrupted by a SIGINT signal (generated, for example, by typing your interrupt character, typically control-C) or a SIGTERM signal (typically generated with the kill command); if run with the -c flag, it will capture packets until it is interrupted by a SIGINT or SIGTERM signal or the specified number of packets have been processed; OPTIONS: -c count, exit after receiving count packets.

packet capture · No. 03
Start

Count and stop

Ten packets, then it stops

A CAPTURE THAT STOPS ITSELF$ tcpdump -i eth0-c 1010 packets captured10 packets received by filtercontrol-Cthe manual waywithout -c it runs until you stop itten lines you read beat ten thousandSIGINT or SIGTERM, or the count: three ways out, only one is planned

Left alone, tcpdump runs until you interrupt it: SIGINT, typically control-C, or SIGTERM from the kill command. On a busy wire that's a firehose you're holding shut with one finger.

-c count closes it cleanly: exit after receiving count packets. Ten lines you will actually read beat ten thousand you won't.

Every exploratory capture in this book starts with a -c. Yours should too.

RUN THIS WEEK

Run tcpdump -i eth0 -c 10 on your own machine and let it stop itself. Count the lines it printed.

Per the tcpdump(1) man page (tcpdump.org, tcpdump 4.99.5), OUTPUT FORMAT, TCP Packets: the general format of a TCP protocol line is src > dst: Flags [tcpflags], seq data-seqno, ack ackno, win window, urg urgent, options [opts], length len; tcpflags are some combination of S (SYN), F (FIN), P (PSH), R (RST), U (URG), W (CWR), E (ECE) or . (ACK), or none if no flags are set; src, dst and flags are always present; the connection sequence with regard to the TCP control bits is: caller sends SYN, recipient responds SYN ACK, caller sends ACK; the first time tcpdump sees a TCP conversation it prints the sequence number from the packet, on subsequent packets the difference between the current packet's sequence number and this initial one is printed.

packet capture · No. 04
Read the line

Reading a TCP line

Flags [S.], seq, ack

ONE LINE TELLS A WHOLE STORYrtsg.1023 > csam.login: Flags [S],seq 768512:768512, win 4096src > dstFlags [S]seq / acklengthScaller opensS.recipient answers.caller confirmsS is SYN, F is FIN, P is PSH, R is RST, and the dot is ACK; none if no flags

One line tells a whole story: src > dst: Flags [S], seq, ack, win, length. Src, dst and flags are always there; the rest appears when the packet has it. The flags are letters: S for SYN, F for FIN, P for PSH, R for RST, and a dot for ACK.

A connection opens in three lines: S, then S. (SYN plus ACK), then a bare dot. Sequence numbers after the first packet print as differences from the first, so they read as byte positions in the stream.

Read the flags cell first. It says what the conversation is doing.

RUN THIS WEEK

Open one connection in a capture, ssh or a web fetch, and find its three opening lines: S, S., dot.

Per the pcap-filter(7) man page (tcpdump.org), PRIMITIVES: host hostnameaddr is true if the source or the destination ARP/IPv4/IPv6/RARP address of the packet is hostnameaddr; hostnameaddr may be an IPv4 or IPv6 host number or a name; a host name must resolve using getaddrinfo, typically DNS or hosts, to at least one address, and if the name resolves to more than one address the primitive evaluates to true as soon as one of the addresses matches; per the tcpdump(1) EXAMPLES: to print all packets arriving at or departing from sundown, tcpdump host sundown.

packet capture · No. 05
Filter language

host

One machine, both ways

ONE MACHINE, BOTH DIRECTIONSsundownarrivingdepartingother machines' chatter: ignored$ tcpdump \ host sundownsrc or dst that machinea name or an IPseveral IPs? any matchthe man page's first example for a reason: start from one host, refine later

host sundown is the man page's first example, and it means both directions: true if the source or the destination address is that machine. One word watches a whole conversation.

The address can be an IPv4 or IPv6 number or a name; names must resolve, via DNS or hosts, and a name with several addresses matches as soon as one of them hits.

Start every investigation from one host. Everything else is a refinement.

RUN THIS WEEK

Run tcpdump -n host on one IP you care about, with -c 20, and read what that machine talks to.

Per the tcpdump(1) man page (tcpdump.org, tcpdump 4.99.5), OPTIONS: -w file, write the raw packets to file rather than parsing and printing them out; they can later be printed with the -r option; standard output is used if file is -; this output will be buffered if written to a file or pipe, so a program reading from the file or pipe may not see packets for an arbitrary amount of time after they are received, use the -U flag to cause packets to be written as soon as they are received; the MIME type application/vnd.tcpdump.pcap has been registered with IANA for pcap files; tcpdump itself doesn't check the extension when reading capture files and doesn't add an extension when writing them (it uses magic numbers in the file header instead), however many operating systems and applications will use the extension if it is present and adding one (e.g. .pcap) is recommended.

packet capture · No. 06
Save and rotate

Write a pcap

-w saves the raw

SAVE THE RAW, NOT THE PARSED-wcapture.pcapraw bytes, nothing decoded, nothing lost-U flushes as they arrivebuffered to files and pipesyou add the .pcaptcpdump never adds the extension itself; it trusts magic numbers, you shouldn't

-w writes raw packets, not parsed lines. Nothing is decoded, nothing is lost; -r prints them later. Give - as the filename and it writes to standard output.

Two honest footnotes. Output to a file or pipe is buffered: a reader may not see packets for a while, and -U flushes as they arrive. And tcpdump never adds an extension; it trusts magic numbers, but the man page recommends adding .pcap yourself.

Printing answers a question. Saving keeps the option to ask better ones.

RUN THIS WEEK

Capture a minute of your own traffic with -w capture.pcap and a -c limit. You'll open it in two pages.

Per the tcpdump(1) man page (tcpdump.org, tcpdump 4.99.5): DESCRIPTION, it can also be run with the -w flag, which causes it to save the packet data to a file for later analysis, and/or with the -r flag, which causes it to read from a saved packet file; reading a saved packet file doesn't require special privileges; OPTIONS: -c count exit after receiving count packets; -h / --help, print the tcpdump and libpcap version strings, print a usage message, and exit; --version, print the version strings and exit.

packet capture · No. 07
Habit

One habit

Capture first, read later

CAPTURE FIRST, READ LATERthe box$ tcpdump -w case.pcap \ -c 50000 port 53first!the evidence,bounded and safelater, calmly, no privileges needed:-r case.pcap host / port / flags-h: usage + versionsthirty pages, one habit: capture first. everything else is reading

When something breaks, the evidence is evaporating. The habit is one reflex: start a bounded capture before you touch anything else. -w to a file, -c so it can't run away, a filter so it's mostly signal.

Reading is the cheap part, and it can wait: a saved file needs no privileges and answers to every filter in this book, as many times as you like. And when in doubt, -h prints the versions and usage; the manual is one flag away.

Thirty pages, one habit: capture first. Everything else is reading.

RUN THIS WEEK

Next time something breaks, start the capture before the first diagnostic command. Then break things calmly.

Index

Index


Count and stop7
Find your interface6
host9
One habit11
Reading a TCP line8
What tcpdump is5
Write a pcap10