Links

Sniffear Tráfico

TCPDump

#Listen to DNS request to discover what is searching the host
sudo tcpdump -i <INTERFACE> udp port 53
#Listen to icmp packets
tcpdump -i <IFACE> icmp
#Capture web traffic from bash
sudo bash -c "sudo nohup tcpdump -i eth0 -G 300 -w \"/tmp/dump-%m-%d-%H-%M-%S-%s.pcap\" -W 50 'tcp and (port 80 or port 443)' &"