tcpdump cheat sheet for netadmins/sysadmins
TCPDump Cheat Sheet for NetAdmins & SysAdmins
1. Basic Capture
Capture on Any Interface
tcpdump -i any Capture on Specific Interface
tcpdump -i eth0 Save Capture to File
Read from a PCAP File
Limit Number of Packets
2. Filtering Traffic
Filter by Host (IP)
Filter by Source/Destination IP
Filter by Port
Filter by Protocol
Filter by Network (CIDR)
Combine Filters (AND/OR)
3. Advanced Filtering (BPF Syntax)
Filter by TCP Flags
Filter by Packet Size
Filter by MAC Address
Filter VLAN Traffic
4. Output & Verbosity
Show IPs Instead of Hostnames
Verbose Output
Print Packet Contents (Hex & ASCII)
Show Absolute Sequence Numbers
Timestamps
5. Advanced Capture & Analysis
Capture Only HTTP Traffic
Capture FTP Passwords (Cleartext)
Capture DNS Queries
Capture ICMP (Ping/Traceroute)
Capture Only SYN Packets (New Connections)
6. Performance & Storage Optimization
Limit Packet Size
Rotate Capture Files
Stop After X MB
Run in Background
7. Common Use Cases
8. Quick Reference Table
tcpdump’s offensive use cases with command examples
Last updated