tcpdump Cheatsheet

Power user.

Overview

tcpdump is the standard packet-capture tool. Five primitive operations cover almost every network investigation: capture, filter, save, replay, decode. Fluency in all five is what turns “the network is weird” into specific packets.

The approach

Three habits separate fluent tcpdump from beginner tcpdump: filter narrowly, save the pcap, and skip name resolution while capturing.

Why this compounds

tcpdump fluency compounds because BPF syntax and the capture-decode pattern transfer across eBPF, Wireshark, ss, and modern observability tools.