Security

tcpdump Filter Builder

Build a Berkeley Packet Filter expression from hosts, ports, protocols and TCP flags, with the full tcpdump command including rotation, snap length and output options.

Last reviewed by the Radiatus Cloud team

Command appears here.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Capture less to see more

Running tcpdump without a filter on a busy interface produces gigabytes of traffic in which the packets you care about are invisible, and on a loaded host the capture itself can drop packets it cannot write fast enough. A Berkeley Packet Filter expression is compiled into bytecode and evaluated in the kernel before the packet is copied to userspace, so filtering is both the way to find the traffic and the way to avoid affecting the system you are debugging.

The syntax has a few traps

Primitives combine with and, or and not, and precedence is not what most people expect: not binds tightest, then and, then or. The expression "host 10.0.0.1 and port 80 or port 443" does not mean what it appears to, because it parses as "(host and port 80) or port 443" and captures every packet on 443 from anywhere. Parentheses fix it, and in a shell they must be quoted or escaped because the shell claims them first.

Beyond hosts and ports

The filter language reaches into packet headers directly, which is where it becomes genuinely powerful. Matching TCP flags isolates connection setup or resets, filtering on header offsets finds HTTP methods without decoding the stream, and combining a VLAN keyword with other primitives works on tagged traffic that otherwise matches nothing. The builder emits these forms with the offsets already correct, which is the part that is tedious to remember.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

Where does BPF filtering happen?

In the kernel, before packets are copied to userspace. That is why a filtered capture has far lower overhead than capturing everything and filtering afterwards, and why a good filter matters most on a busy host.

Why does my "and or" expression capture too much?

Operator precedence. not binds tightest, then and, then or, so "host X and port 80 or port 443" parses as "(host X and port 80) or port 443". Use parentheses, and quote them in a shell.

What snap length should I use?

0 or 262144 captures whole packets, which you want when the payload matters. A snap length of 96 captures headers only, which is much smaller and sufficient for connection level analysis. Older tcpdump defaulted to 68 bytes, which truncates and confuses analysis.

How do I capture without filling the disk?

Use -W with -C to rotate through a fixed number of files of a given size, or -G with -W for time based rotation. The generated command includes both forms so a long running capture cannot exhaust the filesystem.

Can I filter on VLAN tagged traffic?

Yes, but you must say so. A tagged frame shifts every subsequent header by four bytes, so a plain "tcp port 80" filter matches nothing. Prefix with the vlan keyword, which adjusts the offsets for everything after it in the expression.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Set the hosts, ports and protocols you want to capture and copy the generated command.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.