← Downloads

tcpdump 4.99.5

Package v4.99.5 x86_64 TAR.GZ September 15, 2025

Captures and displays network packets with BPF filter expressions, writing pcap files Wireshark can read. The standard tool for finding out what is actually on the wire.

Download TAR.GZ Project website ↗

Download Mirrors

Mirror Region Download
tcpdump.org (Official) Primary Global Download
Release Archive Global Download

tcpdump captures packets and prints them. When a service is unreachable and every configuration looks right, this is how you find out whether the traffic is arriving at all.

The flags that matter

sudo tcpdump -i eth0 -nn -s 0 port 443
sudo tcpdump -i any -nn 'host 10.0.0.5 and not port 22'
sudo tcpdump -i eth0 -nn -c 100 -w capture.pcap

-nn stops name resolution for both hosts and ports. Without it tcpdump does DNS lookups for every address, which is slow and generates traffic that pollutes your own capture.

-s 0 captures full packets rather than truncating.

not port 22 when working over SSH. Without it you capture the packets carrying your own output, which generates more output, which generates more packets. The capture becomes useless and the session may stall.

Filters

tcpdump -nn 'tcp port 80 or tcp port 443'
tcpdump -nn 'src host 192.168.1.5'
tcpdump -nn 'net 10.0.0.0/8'
tcpdump -nn 'icmp'
tcpdump -nn 'tcp[tcpflags] & tcp-syn != 0'     # SYN packets only

These are capture filters in BPF syntax, applied in the kernel before packets are copied. Anything they exclude is gone permanently, which is different from a Wireshark display filter that only decides what you see from data already captured.

Our tcpdump filter builder generates them.

Rotation

sudo tcpdump -i eth0 -nn -s 0 -W 5 -C 100 -w capture.pcap

-C 100 starts a new file every 100MB, -W 5 keeps five and overwrites the oldest. This is what stops a long capture filling the disk.

Capture remotely, analyse locally

ssh user@server "sudo tcpdump -i eth0 -nn -s 0 -w - 'not port 22'" | wireshark -k -i -

The server has the traffic and your desktop has the analysis tools. This one-liner is worth remembering.

Not as root

Packet parsers process hostile input and have a long CVE history. Grant capabilities to the binary rather than running the whole thing as root:

sudo setcap cap_net_raw,cap_net_admin+eip /usr/bin/tcpdump

Verify Your Download

Source releases on tcpdump.org are published with GPG signatures.