packet capture tutorial using tcpdump

preview_player
Показать описание
CAINE 15 - tcpdump


Difficulty Level: beginner
Prerequisites: basic understanding of linux command line
basic understanding of networking

In this video, we will look at using the tcpdump tool to capture packets on the network.

Video timeline
00:00 intro
01:46 tcpdump interfaces, -D option
04:43 filter by hostnames
07:11 filter by network
08:34 filter by port
10:37 filter by protocols
11:30 saving packet data
13:16 analyzing PCAP file



Linux distro:

Virtualization software:

This course was designed to provide information on how to use the command line environment in a Unix/Linux system to accomplish tasks such as imaging, data acquisition, and archiving.  This course covers the basics of Unix/Linux commands that allow users to view and edit text files, obtain hardware and system information, partitioning and formatting, process related commands, manipulating disks and partitions, imaging, archiving, logical acquisition, live system response, and basic networking.

This would be beneficial for folks who are interested in digital forensics, incidence response, system administration, ethical hacking, or just plain linux.  his course covers material for beginners as well as for advanced users. This course would also be helpful if you are considering taking the CompTIA Linux+ certification test.

#tcpdump #networking #DFIR
Рекомендации по теме
Комментарии
Автор

This was awesome. I’m new to cyber security and have been learning tcpdump on hack the box. It was super helpful to have someone explain the commands and what I’m looking at. Thank you

mrd
Автор

Love love this video, I am studying for security+ and it's hard to find good study material for the Linux commands. This showed me a little bit of everything, perfect!

jesseholliday
Автор

Thank you for the amazing video!!! Quick Question: How do I get socket:permission you dont have permission fixed? I'm the host and each time I use tcpdump it shows an error.

geoffgold
Автор

At 1:00 I have a question, what device is this going out to? If I were to do this at my house where I am connected to the WiFi, would I just open the terminal and type tcpdump and I would be able to check the packets sent from a computer in my home to a printer on my network?

IsaacGoytia-ib
Автор

hello Sir, thanks for share, I have a wonder for you, I had captured icmp packet in destination whit tcp dump and I had simulated a failure inside de network but I dont see the missed ICMP packets in pcap capture, Do you know how I see that ? thanks in advance.

luismayorca
Автор

“WL blah blah blah” at 02:35 is the best name for a network interface! Hilarious.

jimweasel