H3AD-REF / CHEATSHEETS / TCPDUMP REFERENCE
tcpdump.
The Flags You Actually Reach For.
A static reference for the tcpdump CLI: basic syntax, BPF capture filter grammar, the one-liners that come up in every packet-triage session, and the output flags that change what you see, not what gets captured. No live capture here, just the syntax. For filtering what you've already captured, see Wireshark Display Filters.
Basic Syntax
Three flags cover most of what you'll type before a filter expression ever enters the picture.
SYNTAX
Live Capture
The command you reach for first, on the box, right now
tcpdump -i eth0 -n -X — capture on interface eth0, skip DNS resolution on every address with -n, and dump each packet's payload as hex and ASCII with -X. Dropping DNS resolution matters more than it looks: without -n, tcpdump fires a reverse lookup per new host and can visibly lag a busy capture.SYNTAX
Write To File
Capture now, read and filter later
tcpdump -i eth0 -w file.pcap writes raw packets to disk instead of printing them. Nothing is decoded or filtered on the way in beyond whatever BPF expression you passed, so the file holds exactly what the wire held. Read it back with the flag below.SYNTAX
Read From File
Every other flag in this cheatsheet still applies offline
tcpdump -r file.pcap replays a saved capture through the same display and filter logic as a live one. Add -n, -X, a BPF filter, or any output flag exactly as you would live; tcpdump doesn't distinguish disk from wire once it's parsing frames.BPF Capture Filter Syntax
Berkeley Packet Filter primitives, the vocabulary every filter expression is built from.
BPF
host
Match traffic to or from one address
tcpdump host 10.0.0.5 — captures anything where 10.0.0.5 shows up as source or destination. Matches both directions by default; narrow it with src host or dst host when direction matters.BPF
net
Match a whole subnet instead of one host
tcpdump net 10.0.0.0/24 — captures any packet whose source or destination falls inside the given CIDR block. Useful for watching a segment rather than chasing one IP across a NAT boundary.BPF
port
Match a single TCP or UDP port, either direction
tcpdump port 443 — captures traffic where 443 is the source or destination port, TCP or UDP. Pair with tcp or udp ahead of it, as in tcp port 443, to pin the protocol.BPF
portrange
Match a contiguous block of ports in one expression
tcpdump portrange 8000-8010 — captures traffic on any port from 8000 through 8010 inclusive, saving you an or chain across eleven separate port clauses.BPF
proto
Match by IP protocol number or name, below TCP/UDP
tcpdump proto icmp — captures traffic by protocol name (icmp, udp, tcp) or number, for cases where the traffic you're after doesn't ride on a port at all, like ICMP echo requests.Common One-Liners
The filter patterns that show up in nearly every packet-triage session, ready to paste.
PATTERN
SYN-Only Capture
Isolate connection attempts, not the sessions that follow
tcpdump 'tcp[tcpflags] & tcp-syn != 0' — matches any TCP packet with the SYN flag set, including SYN-ACK. Good for spotting scan sweeps or counting distinct connection attempts without wading through full session traffic.PATTERN
DNS Traffic
Watch resolution activity in isolation
tcpdump port 53 — captures DNS queries and responses over both UDP and TCP. First stop for chasing a suspicious domain or confirming a host is even resolving what you expect it to.PATTERN
HTTP Traffic
Plaintext web traffic, before TLS enters the picture
tcpdump port 80 — captures unencrypted HTTP. Combine with -A (see Output Flags) to read request lines and headers straight off the wire instead of decoding hex by hand.PATTERN
Exclude SSH
Keep your own remote session out of the capture
tcpdump not port 22 — filters out SSH traffic, which matters when you're running tcpdump over an SSH session on the same box: without this, your own terminal traffic floods the capture you're trying to read.PATTERN
Specific Host Pair
Narrow to one conversation, both directions
tcpdump host 10.0.0.1 and host 10.0.0.2 — captures only packets exchanged between these two addresses, dropping everything else. The cleanest way to isolate a single suspect conversation on a busy segment.Output Flags
These change what tcpdump shows you or how much it captures per packet, not which packets match.
FLAG
-c (count)
Stop after a fixed number of packets
tcpdump -c 100 — exits automatically once 100 packets have matched the filter. Useful for a quick sanity check without babysitting the terminal or piping through head.FLAG
-s (snaplen)
How many bytes of each packet get captured
tcpdump -s 0 — captures the full packet with no truncation. Older tcpdump defaults truncated at 68 or 96 bytes to save space; modern versions default to full capture, but setting -s 0 explicitly makes the intent clear and avoids surprises when replaying old habits on old builds.FLAG
-v / -vv / -vvv
More detail in the header summary, each level adds more
Each additional
v prints more protocol-level detail per packet: TTL, ID, checksums, and options at -v, deeper still at -vv and -vvv. Useful when the one-line summary doesn't tell you enough, expensive on screen space when it's running against a busy interface.FLAG
-A (ASCII)
Print packet payload as readable text
tcpdump -A — prints each packet's payload in ASCII instead of hex. Fastest way to read plaintext protocols like HTTP or SMTP directly off the wire, less useful once TLS is in the way.FLAG
-e (link-layer)
Show the header most filters never mention
tcpdump -e — prints the link-layer header on every line, including source and destination MAC addresses. Matters on a switched segment where you need to know which physical host actually sent a frame, not just which IP claims to have.