Packet Capture Notes


Filter where the source ip is not

ip.src !=

Filter where the destination ip is not

ip.dst !=

Find packets with a string in them

frame contains <thing to search>

For example:

frame contains google



Filter on port 80

tcpdump port 80

Filter on source port 80

tcpdump src port 80

Destination port 80

tcpdump dest port 80

All traffic for

tcpdump host

Save output

tcpdump tcp -w output.pcap


Filter on service

In this case, we are filtering icmp traffic on the eth0 interface where the ICMP type field value is icmp-echo. We finish it with a full protocol decode (-vv) aka verbose output.

tcpdump -i eth0 icmp and icmp[icmptype]=icmp-echo -vv


Listen for traffic over port 389

tcpdump -i eth0 -nn port 389