List interfaces:
tcpdump -D
Capture on an interface:
sudo tcpdump -i eth0 -nn
Filter examples:
sudo tcpdump -i eth0 -nn host 1.1.1.1
sudo tcpdump -i eth0 -nn port 53
sudo tcpdump -i eth0 -nn tcp and port 443
sudo tcpdump -i eth0 -nn 'icmp or icmp6'
Write to pcap:
sudo tcpdump -i eth0 -nn -w capture.pcap
Workflow:
.pcapdns, tcp.port == 443)-nn to avoid slow DNS/service-name lookups