2025-03-14 21:59:59 -06:00
|
|
|
# ngrep
|
|
|
|
|
|
|
|
|
|
> Filter network traffic packets using regular expressions.
|
2025-05-08 12:26:01 -06:00
|
|
|
> More information: <https://github.com/jpr5/ngrep/blob/master/EXAMPLES.md>.
|
2025-03-14 21:59:59 -06:00
|
|
|
|
|
|
|
|
- Capture traffic of all interfaces:
|
|
|
|
|
|
|
|
|
|
`ngrep -d any`
|
|
|
|
|
|
|
|
|
|
- Capture traffic of a specific interface:
|
|
|
|
|
|
|
|
|
|
`ngrep -d {{eth0}}`
|
|
|
|
|
|
|
|
|
|
- Capture traffic crossing port 22 of interface eth0:
|
|
|
|
|
|
|
|
|
|
`ngrep -d {{eth0}} port {{22}}`
|
|
|
|
|
|
|
|
|
|
- Capture traffic from or to a host:
|
|
|
|
|
|
|
|
|
|
`ngrep host {{www.example.com}}`
|
|
|
|
|
|
|
|
|
|
- Filter keyword 'User-Agent:' of interface eth0:
|
|
|
|
|
|
|
|
|
|
`ngrep -d {{eth0}} '{{User-Agent:}}'`
|