The only Linux command you need for monitoring network traffic - and how to use it
ID: b17d83f4-4714-5655-bd82-da927de169c5
STIX ID: report--b17d83f4-4714-5655-bd82-da927de169c5
Feed Name: ZDNet Security
This article provides a practical guide to monitoring Linux network traffic with the iftop command, including installation steps for Ubuntu, Fedora, and Arch, identifying the correct interface via `ip a`, and running `sudo iftop -i INTERFACE`. It explains how to read incoming (`<=`) and outgoing (`=>`) traffic, suggests using Whois to investigate suspicious IPs, and advises blocking questionable addresses via a firewall, positioning iftop as a simple alternative to more complex tools like Wireshark.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
