Getting Started With TCPDump
ID: cb209afe-2e78-563b-87bf-cad0c1c34af5
STIX ID: report--cb209afe-2e78-563b-87bf-cad0c1c34af5
Feed Name: Black Hills Infosec Blog
This tutorial introduces getting started with tcpdump: identifying interfaces, running with sudo, using -XA to view packet data in hex and ASCII, and generating traffic with ping and netcat to observe unencrypted payloads. It also demonstrates reading from and writing to pcap files for offline analysis, with a brief mention of inspecting a capture containing command-and-control/backdoor traffic as an example scenario.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
