tcpdump, one move per page
Thirty moves for the person who ssh'd into a box because the network is slow: -D to find the wire, -c to stop cleanly, -n to skip the name lookups, host, src, port and net to sieve the traffic, tcp[tcpflags] to see handshakes and resets, -w to save the raw pcap and -r to read it back, -G, -C and -W to rotate the files before they fill the disk, -A and -X to look inside a payload, and the exit tally that tells you when you dropped packets without knowing.
A diagram, the command, and one thing to go run this week. That's a page.
tcpdump, one move per page
Thirty moves for the person who ssh'd into a box because the network is slow: -D to find the wire, -c to stop cleanly, -n to skip the name lookups, host, src, port and net to sieve the traffic, tcp[tcpflags] to see handshakes and resets, -w to save the raw pcap and -r to read it back, -G, -C and -W to rotate the files before they fill the disk, -A and -X to look inside a payload, and the exit tally that tells you when you dropped packets without knowing.
Set in Space Grotesk, Inter and JetBrains Mono (SIL Open Font License).
Every flag, filter, default and number in this book is as the official sources state it, fetched and read during this build: the tcpdump(1) man page, version 4.99.5, and the pcap-filter(7) man page (tcpdump.org, The Tcpdump Group). Demand evidence from live beginner searches and cheat-sheet popularity, fetched this build; no facts are sourced from cheat sheets or Reddit. Teaching conventions (one move a page) are named as conventions. Capturing traffic on networks you do not own may require permission and may be restricted by law.
General information only. Not professional advice; check flags against your own tcpdump version, which may differ.
© 2026 Steve Hodgkiss. All rights reserved. Personal use only; no redistribution rights.
Edition 1.0 · stevehodgkiss.net
Contents
Start
What tcpdump prints, how to name the interface you mean, and how to make a capture stop itself.
- 01What tcpdump is
- 02Find your interface
- 03Count and stop
Per the tcpdump(1) man page (tcpdump.org, tcpdump 4.99.5), DESCRIPTION: tcpdump prints out a description of the contents of packets on a network interface that match the Boolean expression; the description is preceded by a time stamp, printed by default as hours, minutes, seconds, and fractions of a second since midnight; it can also be run with the -w flag, which causes it to save the packet data to a file for later analysis, and/or with the -r flag, which causes it to read from a saved packet file rather than to read packets from a network interface; in all cases, only packets that match the expression will be processed by tcpdump.
What tcpdump is
Tcpdump prints a description of the contents of packets on a network interface that match the Boolean expression. Each line is preceded by a time stamp: hours, minutes, seconds and fractions of a second since midnight.
Two directions, later. -w saves the raw packet data to a file for later analysis; -r reads from a saved file instead of an interface. In all cases, only packets matching the expression are processed.
Print now, or save for later. Every page in this book does one of the two.
Run tcpdump on any box you're allowed to, watch three lines scroll past, then stop it with control-C.
Per the tcpdump(1) man page (tcpdump.org, tcpdump 4.99.5), OPTIONS: -D / --list-interfaces prints the list of the network interfaces available on the system and on which tcpdump can capture packets, for each interface a number and an interface name, possibly followed by a text description; -i interface / --interface= listens on that interface; if unspecified, tcpdump searches the system interface list for the lowest numbered, configured up interface (excluding loopback), which may turn out to be eth0; on Linux systems with 2.2 or later kernels, and on recent macOS and Solaris, an interface argument of any can be used to capture packets from all interfaces; note that captures on the any pseudo-interface will not be done in promiscuous mode; an interface number as printed by -D can be used as the -i argument.
Find your interface
Before anything, name the wire. tcpdump -D lists every interface it can capture on, each with a number, a name, maybe a description. That number works as the -i argument too.
Run bare tcpdump and it picks for you: the lowest numbered, configured up interface, excluding loopback, which the man page says may turn out to be eth0. Linux, recent macOS and Solaris also accept any, all interfaces at once, with one caveat: captures on any are not promiscuous.
-D once, -i forever. Don't let the tool guess the wire.
Run tcpdump -D today and write down which interface carries your traffic. Every later command names it.
Per the tcpdump(1) man page (tcpdump.org, tcpdump 4.99.5), DESCRIPTION: tcpdump will, if not run with the -c flag, continue capturing packets until it is interrupted by a SIGINT signal (generated, for example, by typing your interrupt character, typically control-C) or a SIGTERM signal (typically generated with the kill command); if run with the -c flag, it will capture packets until it is interrupted by a SIGINT or SIGTERM signal or the specified number of packets have been processed; OPTIONS: -c count, exit after receiving count packets.
Count and stop
Left alone, tcpdump runs until you interrupt it: SIGINT, typically control-C, or SIGTERM from the kill command. On a busy wire that's a firehose you're holding shut with one finger.
-c count closes it cleanly: exit after receiving count packets. Ten lines you will actually read beat ten thousand you won't.
Every exploratory capture in this book starts with a -c. Yours should too.
Run tcpdump -i eth0 -c 10 on your own machine and let it stop itself. Count the lines it printed.
Per the tcpdump(1) man page (tcpdump.org, tcpdump 4.99.5), OUTPUT FORMAT, TCP Packets: the general format of a TCP protocol line is src > dst: Flags [tcpflags], seq data-seqno, ack ackno, win window, urg urgent, options [opts], length len; tcpflags are some combination of S (SYN), F (FIN), P (PSH), R (RST), U (URG), W (CWR), E (ECE) or . (ACK), or none if no flags are set; src, dst and flags are always present; the connection sequence with regard to the TCP control bits is: caller sends SYN, recipient responds SYN ACK, caller sends ACK; the first time tcpdump sees a TCP conversation it prints the sequence number from the packet, on subsequent packets the difference between the current packet's sequence number and this initial one is printed.
Reading a TCP line
One line tells a whole story: src > dst: Flags [S], seq, ack, win, length. Src, dst and flags are always there; the rest appears when the packet has it. The flags are letters: S for SYN, F for FIN, P for PSH, R for RST, and a dot for ACK.
A connection opens in three lines: S, then S. (SYN plus ACK), then a bare dot. Sequence numbers after the first packet print as differences from the first, so they read as byte positions in the stream.
Read the flags cell first. It says what the conversation is doing.
Open one connection in a capture, ssh or a web fetch, and find its three opening lines: S, S., dot.
Per the pcap-filter(7) man page (tcpdump.org), PRIMITIVES: host hostnameaddr is true if the source or the destination ARP/IPv4/IPv6/RARP address of the packet is hostnameaddr; hostnameaddr may be an IPv4 or IPv6 host number or a name; a host name must resolve using getaddrinfo, typically DNS or hosts, to at least one address, and if the name resolves to more than one address the primitive evaluates to true as soon as one of the addresses matches; per the tcpdump(1) EXAMPLES: to print all packets arriving at or departing from sundown, tcpdump host sundown.
host
host sundown is the man page's first example, and it means both directions: true if the source or the destination address is that machine. One word watches a whole conversation.
The address can be an IPv4 or IPv6 number or a name; names must resolve, via DNS or hosts, and a name with several addresses matches as soon as one of them hits.
Start every investigation from one host. Everything else is a refinement.
Run tcpdump -n host on one IP you care about, with -c 20, and read what that machine talks to.
Per the tcpdump(1) man page (tcpdump.org, tcpdump 4.99.5), OPTIONS: -w file, write the raw packets to file rather than parsing and printing them out; they can later be printed with the -r option; standard output is used if file is -; this output will be buffered if written to a file or pipe, so a program reading from the file or pipe may not see packets for an arbitrary amount of time after they are received, use the -U flag to cause packets to be written as soon as they are received; the MIME type application/vnd.tcpdump.pcap has been registered with IANA for pcap files; tcpdump itself doesn't check the extension when reading capture files and doesn't add an extension when writing them (it uses magic numbers in the file header instead), however many operating systems and applications will use the extension if it is present and adding one (e.g. .pcap) is recommended.
Write a pcap
-w writes raw packets, not parsed lines. Nothing is decoded, nothing is lost; -r prints them later. Give - as the filename and it writes to standard output.
Two honest footnotes. Output to a file or pipe is buffered: a reader may not see packets for a while, and -U flushes as they arrive. And tcpdump never adds an extension; it trusts magic numbers, but the man page recommends adding .pcap yourself.
Printing answers a question. Saving keeps the option to ask better ones.
Capture a minute of your own traffic with -w capture.pcap and a -c limit. You'll open it in two pages.
Per the tcpdump(1) man page (tcpdump.org, tcpdump 4.99.5): DESCRIPTION, it can also be run with the -w flag, which causes it to save the packet data to a file for later analysis, and/or with the -r flag, which causes it to read from a saved packet file; reading a saved packet file doesn't require special privileges; OPTIONS: -c count exit after receiving count packets; -h / --help, print the tcpdump and libpcap version strings, print a usage message, and exit; --version, print the version strings and exit.
One habit
When something breaks, the evidence is evaporating. The habit is one reflex: start a bounded capture before you touch anything else. -w to a file, -c so it can't run away, a filter so it's mostly signal.
Reading is the cheap part, and it can wait: a saved file needs no privileges and answers to every filter in this book, as many times as you like. And when in doubt, -h prints the versions and usage; the manual is one flag away.
Thirty pages, one habit: capture first. Everything else is reading.
Next time something breaks, start the capture before the first diagnostic command. Then break things calmly.