·抓包
tcpdump -i eth0 -s 0 -w file.pcap
·读取抓包文件
tcpdump -r file.pcap
·ASCII读取抓包文件
tcpdump -A -r file.pcap
·16进制读取文件
tcpdump -x -r file.pcap
·筛选
tcpdump -n -r file.pcap | awk'{print $3}' | sort -u tcpdump -n src host 192.168.1.103 -r file.pcap tcpdump -n dst host 192.168.1.103 -r file.pcap tcpdump -n port 80 -r file.pcap