tcpdump
Commands
tcpdump --versiontcpdump -Dtcpdump -i InterfaceNametcpdump -ntcpdump -nntcpdump -etcpdump -Xtcpdump -XXtcpdump -v
tcpdump -vv
tcpdump -vvvtcpdump -Stcpdump -qtcpdump -i InterfaceName -w file.pcaptcpdump -r file.pcaptcpdump -w capture_file.pcapFilters
tcpdump src host 192.168.1.1 && port 80tcpdump src host 192.168.1.1 or dst host 192.168.1.2tcpdump not udptcpdump -c 10tcpdump -s 64tcpdump greater 1000
tcpdump less 500tcpdump src host 192.168.1.1
tcpdump dst host 192.168.1.1tcpdump net 192.168.1.0/24tcpdump -i (int) host (ip)tcpdump -i (int) port (#)tcpdump portrange 1000-2000tcpdump -i (int) proto ICMPtcpdump -i (int) proto 6Protocol Number List
ICMP(Internet Control Message Protocol) ->1IGMP(Internet Group Management Protocol) ->2TCP(Transmission Control Protocol) ->6UDP(User Datagram Protocol) ->17OSPF(Open Shortest Path First) ->89EIGRP(Enhanced Interior Gateway Routing Protocol) ->88AH(Authentication Header) ->51ESP(Encapsulating Security Payload) ->50GRE(Generic Routing Encapsulation) ->47IPv6(Internet Protocol version 6) ->41IPv4(Internet Protocol version 4) ->4DCCP(Datagram Congestion Control Protocol) ->33SCTP(Stream Control Transmission Protocol) ->132RARP(Reverse Address Resolution Protocol) ->3PPTP(Point-to-Point Tunneling Protocol) ->115MPLS(Multiprotocol Label Switching) ->89X.25->93FDDI(Fiber Distributed Data Interface) ->97
Last updated