0PricingLogin
Cyber Security Academy · Lesson

Capturing Packets

Use Wireshark and tcpdump.

Why Capture Packets

Packet capture records the raw network traffic flowing across an interface. It is the ground truth of what actually happened on the wire.

Analysts use captures to investigate incidents, debug protocols, and hunt for malicious activity.

Two Core Tools

The two essential tools are Wireshark, a graphical analyzer, and tcpdump, a command-line capture tool.

  • tcpdump: lightweight, perfect for servers and remote capture.
  • Wireshark: rich GUI for deep analysis.

All lessons in this course

  1. Capturing Packets
  2. Reading Protocols
  3. Detecting Anomalies
  4. Extracting Artifacts
← Back to Cyber Security Academy