For all you #PCAP ninjas, I feel like I should throw a shout-out to "tshark -Tfields ..." which is basically "awk" for packets. tcpdump is great for breaking down huge PCAPs. But once they are a manageable size, nothing beats tshark for extracting just the fields you need.

Nov 11, 2022 · 12:58 PM UTC

2
6