Windows build + Npcap
ManualnpcapOfficialUse the winpcap/npcap-based build from the official download page.
Open official sourceCommand-line packet capture and filter reader
tcpdump captures packets through libpcap and prints decoded summaries. It is what you use on a headless server, inside a container, or whenever you want a capture file you can hand to Wireshark.
The BPF expressions it accepts are the same ones Wireshark uses for capture filters, which makes it the natural place to learn filtering: small, explicit, no GUI.
Supported platforms
8
Documented install or usage guidance
Learning curve
beginner
Difficulty of becoming productive, not of the underlying theory
Tags
capture, pcap, bpf, diagnostics, server
Dataset entry
tcpdump.ts
Reviewed 2026-01-11
Grouped by platform. Elevation requirements are marked per method.
Use the winpcap/npcap-based build from the official download page.
Open official sourcesudo tcpdump -Di en0
Needs elevated privileges (sudo / Administrator).
sudo apt install tcpdump
sudo dnf install tcpdump
Package availability follows your distribution and enabled repositories. Entry revised 11 Jan 2026 — confirm the current release on the project's own download page.
Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.
The default diagnostic: readable output, no DNS or name lookups so nothing hangs.
sudo tcpdump -nn -i any host 192.0.2.10 and port 443
Notes
Ring-buffered capture that cannot fill the disk during a long-lived investigation.
sudo tcpdump -i eth0 -w /tmp/edge.pcap -C 50 -W 5 'port 53 or port 443'
Notes
Re-reads a file with an expression applied at read time, which is how you isolate one TCP stream.
sudo tcpdump -nn -r /tmp/edge.pcap 'tcp[tcpflags] & (tcp-syn|tcp-rst) != 0'
Captures a fixed number of packets and prints interface statistics on exit.
sudo tcpdump -nn -i eth0 -c 200 -e
Notes
Prove whether packets arrive at all before blaming the application.
Look at query names, response codes and handshake failures.
Bounded captures as an attachment to an incident record.
Symptoms you will actually hit, with the cause and the legitimate fix.
Possible causes
Usual fix
List devices with `tcpdump -D` or `ip -br link`, and capture inside the correct namespace (`nsenter -n -t <pid>`).
Possible causes
Usual fix
Remove the filter and retest; build expressions up one term at a time.
Possible causes
Usual fix
Capture with `-s 0` on the interface under test, and remember that encrypted payload stays encrypted.
Not documented yet: tshark. Request an entry and it will link up automatically.Request a tool
Side-by-side
Where to verify anything on this page. External links open in a new tab.
Wireshark cover adjacent parts of the same job.