What's a tcpdump one-liner to dump a TCP stream that matches a given substring?
-
03-07-2019 - |
Question
Is there a quick tcpdump one-liner to print out a TCP stream that matches a particular substring -- or, if that's not easy, how about printing out just the single TCP packet that matches the substring?
Solution
The best option is to use ngrep rather than tcpdump. Ngrep is designed to do exactly what you're after.
Licensed under: CC-BY-SA with attribution
Not affiliated with StackOverflow