A practical reference for sysadmins using tcpdump to capture network traffic, detect active intrusions, and produce forensic-grade evidence of data exfiltration.

What is tcpdump?

tcpdump is a command-line packet analyser that captures and displays network traffic passing through a network interface in real time or writes it to a pcap file for later analysis. It uses the libpcap library and the Berkeley Packet Filter (BPF) syntax for filtering, making it the foundation for many network security tools including Wireshark, Snort, and Zeek. For sysadmins responding to a suspected intrusion, tcpdump provides the most direct evidence of what is actually traversing the network: the content of a C2 beacon, the destination and volume of an exfiltration transfer, or the specific protocol anomaly triggering a security alert. Unlike netstat or ss which show socket states, tcpdump captures the actual packet content — giving you the payload, not just the connection metadata. pcap files captured with tcpdump can be opened in Wireshark for detailed analysis, shared with security teams, or submitted to threat intelligence platforms.

Syntax

tcpdump -i eth0
tcpdump -i eth0 -n host 203.0.113.45
tcpdump -i eth0 -n port 4444
tcpdump -i eth0 -w /tmp/capture.pcap
tcpdump -i eth0 -n -w /tmp/capture.pcap host 203.0.113.45
tcpdump -r /tmp/capture.pcap

The -i flag specifies the network interface (use tcpdump -D to list available interfaces). The -n flag disables hostname resolution. The -w flag writes raw packets to a pcap file. The -r flag reads and displays a previously captured pcap file. BPF filter expressions (host, port, net, src, dst) are appended after the flags.

Key Options and Flags

Flag / ParameterDescriptionSecurity Note
-i <interface>Specify the network interface to capture on (e.g. eth0, ens3, any)Use 'any' to capture on all interfaces — required if the attack traffic enters on a different interface
-nDisable hostname and port name resolutionAlways use -n during investigations to prevent DNS queries that could alert an attacker monitoring their DNS
-w <file>Write raw packets to a pcap file instead of displaying themRequired for forensic evidence preservation — console output cannot be replayed or analysed in Wireshark
-r <file>Read and display packets from a saved pcap file—
-c <count>Capture a specific number of packets then exit—
-s 0Capture the full packet content, not just the header (snaplen = 0 means unlimited)Required to capture payload content for data exfiltration analysis — default snaplen truncates packets
host <ip>Filter to traffic involving a specific IP addressUse to capture all traffic to/from a suspected C2 server IP
port <num>Filter to traffic on a specific port numberTarget non-standard ports used by known malware families (e.g. 4444 Metasploit, 1234, 31337)

Common Use Cases

Capture All Traffic from a Suspicious IP for Forensic Analysis

When a suspicious IP is identified via netstat or ss, capturing all traffic to and from that IP provides the packet-level evidence needed to determine what data was transmitted. Write to a pcap for offline analysis rather than trying to interpret the live stream in a terminal.

tcpdump -i eth0 -n -s 0 -w /tmp/suspicious_ip_$(date +%Y%m%d_%H%M%S).pcap host 203.0.113.45

Monitor a Non-Standard Port for Backdoor Activity

Backdoors and reverse shells commonly use non-standard ports to avoid detection. Capturing traffic on a specific suspicious port allows you to observe the protocol and content of the connection to confirm whether it is malicious before taking action.

tcpdump -i any -n -s 0 port 4444

Capture Outbound Traffic to Detect Data Exfiltration

Data exfiltration produces large outbound transfers to external IPs. Capturing outbound traffic and monitoring the volume and destination helps identify active exfiltration campaigns. Use -w to write to file and rotate captures with -C to limit individual file size.

tcpdump -i eth0 -n -s 0 -w /tmp/outbound.pcap -C 100 'dst net not 10.0.0.0/8 and dst net not 192.168.0.0/16'

Security Relevance: Capturing Packet-Level Evidence of Active Intrusion

During an active intrusion, tcpdump is the only tool that can capture the actual content of malicious network traffic before it disappears. Connection metadata from netstat or ss tells you that a connection exists and who owns it. tcpdump tells you what is being transmitted. This distinction matters for several reasons: a C2 channel using HTTP to blend with legitimate web traffic is invisible at the socket level but obvious in packet content; a credential-stealing malware transmitting username/password pairs to an external server produces distinctive payload patterns; a DNS-based exfiltration tool encodes data in query subdomains that only appear in packet captures, not in connection listings. pcap files are also the accepted forensic evidence format. Captures taken with proper chain-of-custody procedures are admissible in legal proceedings and required by most incident response frameworks. Establish a capture as early as possible in an incident investigation — evidence that was not captured cannot be recovered.

  • Capturing packets on a production server generates significant disk I/O — use -C to rotate capture files and monitor available disk space
  • tcpdump output in a terminal is difficult to analyse in real time — always write to pcap with -w and analyse in Wireshark
  • Avoid using -n when you need hostname context, but use it by default to prevent DNS lookups during sensitive investigations
  • Running tcpdump itself may be detectable by sophisticated attackers monitoring process lists — consider capturing from a network tap or cloud flow logs where available

Practical Examples

Capture all traffic from a suspicious IP to a pcap for forensic analysis

tcpdump -i eth0 -n -s 0 -w /tmp/evidence_$(date +%Y%m%d_%H%M%S).pcap host 203.0.113.45

Captures the full packet content of all traffic to and from the target IP. The timestamped filename maintains evidence integrity. Use -s 0 to ensure full payload capture rather than truncated headers.

Live display of all non-standard port connections for rapid triage

tcpdump -i any -n 'not port 22 and not port 80 and not port 443'

Filters out known-good SSH, HTTP, and HTTPS traffic to surface unexpected connections on other ports. Useful for quickly identifying C2 or exfiltration channels during initial triage.

Capture rotating files for sustained monitoring

tcpdump -i eth0 -n -s 0 -w /tmp/capture_%Y%m%d_%H%M%S.pcap -G 3600 -Z root

Writes a new pcap file every 3600 seconds (1 hour) using strftime formatting in the filename. Suitable for sustained monitoring during an incident investigation without filling the disk with a single large file.

Troubleshooting Common Issues

Problem: tcpdump is not capturing any packets even though traffic exists

Solution: Verify the correct interface with tcpdump -D to list all available interfaces. On systems with multiple interfaces or VLANs, traffic may be entering on a different interface than expected. Use -i any to capture on all interfaces simultaneously during initial triage.

Problem: The pcap file is growing too large and filling the disk

Solution: Use -C <size_MB> to rotate to a new file when the current one reaches the size limit, and -W <count> to limit the total number of rotation files, creating a circular buffer. Example: tcpdump -i eth0 -w /tmp/cap.pcap -C 50 -W 10 keeps at most 500MB of captures.

Problem: Permission denied when running tcpdump as a non-root user

Solution: tcpdump requires raw socket access, which requires root or the CAP_NET_RAW capability. Run with sudo tcpdump or grant the capability with setcap cap_net_raw+ep $(which tcpdump). Avoid the latter on shared systems as it allows any user to capture network traffic.

Summary

tcpdump is the definitive tool for capturing network-level forensic evidence during a security incident. Its ability to record the full packet content of suspicious connections — not just connection metadata — makes it indispensable for confirming C2 channels, detecting data exfiltration, and producing evidence for incident documentation. Always write to pcap with -w and use -s 0 for full payload capture.

  • Always use -w to write captures to a pcap file — live terminal output cannot be replayed or analysed in Wireshark
  • Use -s 0 to capture full packet payloads — the default snaplen truncates packets and loses payload content
  • Start a tcpdump capture as early as possible in an incident — network evidence that is not captured cannot be recovered

Is Your Linux Server Monitored 24/7?

INTRAM provides managed Linux hosting with continuous security monitoring, automated alerting, and expert response — so your team focuses on building, not firefighting.

Explore Managed Hosting

Let’s assess what your business actually needs.

We will use these details only to understand your request and reply appropriately.