From dankwiki
Revision as of 16:29, 21 December 2011 by Dank (talk | contribs) (→‎Recipes)

Important flags

  • -n to disable (per-packet blocking) DNS lookups
  • -s snaplen to capture more than the default snapshot length. 0 for no limit.


  • Capture all arp: tcpdump arp
  • Capture packets to or from a MAC address M: tcpdump ether host M