On this page
Overview
tcpdump captures network packets or reads them from saved files and prints protocol details in a terminal. Berkeley Packet Filter expressions narrow troubleshooting to the relevant name resolution, connection setup, retransmission, or path.
Features and best fit
Hands-on tested within the scope below · Content checked:
Key features
Best fit
Before adoption
What to check before use
Live capture needs platform-specific privileges and correct interface selection, and packets may contain sensitive data. This guide performs no live capture. GitHub reports NOASSERTION; the pinned LICENSE contains multiple copyright and redistribution notices that must be reviewed for the shipped scope.
local tcpdump 4.99.1 / guide source 4.99.7 / macOS, Apple tcpdump 4.99.1, libpcap 1.10.1, synthetic PCAP file
Read one synthetic UDP packet from disk and compiled its destination-port filter; no live capture, root privilege, or network was used.
Official sources
- [1]the-tcpdump-group/tcpdump README at tcpdump-4.99.7(2026-10-05)
- [2]tcpdump official documentation(2026-10-05)
- [3]tcpdump tcpdump-4.99.7 source(2026-10-05)
- [4]the-tcpdump-group/tcpdump LICENSE at tcpdump-4.99.7(2026-10-05)
- [5]the-tcpdump-group/tcpdump GitHub metadata(2026-10-05)
Supplemental curator note
It is useful for filtering facts from an existing capture without adding capture privileges. Verify -r and the filter against a synthetic packet first, then define storage and sharing boundaries for real data.
Try it in 3 steps
- 1
Create an offline PCAP
Requires Python 3 and tcpdump. Write one UDP packet between documentation addresses in PCAP 2.4 format. No live capture occurs.
demo=$(mktemp -d "${TMPDIR:-/tmp}/tcpdump-offline.XXXXXX") && cd "$demo" && python3 -c 'import struct,socket; eth=bytes.fromhex("00112233445566778899aabb0800"); ip=bytes.fromhex("450000200000000040110000")+socket.inet_aton("192.0.2.1")+socket.inet_aton("198.51.100.2"); udp=struct.pack("!HHHH",12345,53,12,0)+b"test"; pkt=eth+ip+udp; open("sample.pcap","wb").write(struct.pack("<IHHIIII",0xa1b2c3d4,2,4,0,0,65535,1)+struct.pack("<IIII",0,0,len(pkt),len(pkt))+pkt)' - 2
Read only UDP port 53
Read the saved file with -r and require the UDP destination-port-53 filter to print the expected source and destination.
tcpdump -nn -r sample.pcap 'udp dst port 53' 2>/dev/null | grep '192.0.2.1.12345 > 198.51.100.2.53' - 3
Inspect compiled BPF instructions
Compile the same filter with -d against the saved link type and require its accepting BPF return instruction.
tcpdump -d -r sample.pcap 'udp dst port 53' 2>/dev/null | grep 'ret.*#65535'
Growth
Growth trends · Last 30 days
3,242 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 12
- Open PRs
- 67
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- pcap
- pcapng
- packet-capture
- sniffer
- tcpdump
- libpcap
- berkeley-packet-filter
- bsd-packet-filter
- bpf
- auditing
- security
- troubleshooting
- Stars
- 3,242
- Forks
- 936
- Watchers
- 126
- Open issues
- 67
- Contributors
- 174
- Owner type
- Organization
- Primary language
- C
- License
- Not determined
- Repository last updated
- Sep 21, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- Wireshark9,958 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Capture, filter, and dissect packets with the Wireshark GUI and TShark for deep protocol and traffic analysis
C - RIOT5,807 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Run soft real-time IoT workloads across many microcontrollers and network stacks
C - Samba1,144 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Share files over SMB from Linux and Unix and integrate with Windows and Active Directory
C - WireGuard Tools723 Stars
2 shared tag(s) · 1 shared category(s) · Same language
Configure WireGuard peers and keys with
Cwgand usewg-quickfor simple addresses, routes, and DNS setup - curl43,060 Stars
1 shared tag(s) · 1 shared category(s) · Same language
share URL-based transfer capabilities between a CLI and libcurl
C - openssl30,891 Stars
1 shared tag(s) · 1 shared category(s) · Same language
Support TLS communication and cryptographic operations with libraries and commands
C
Report incorrect information
Tell us if any listing information is incorrect or outdated.