Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ptcpdump β€” eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting tcpdump-compatible filtering and PcapNG output. | Kitploit
Tools/GitHubGitHub/mozillazg/ptcpdump
Packet Sniffing & AnalysisContainer SecurityDynamic Analysis (Sandboxing)Network ForensicsForensicsNetwork SecurityDigital ForensicsCloud Security
GitHubmozillazg/ptcpdump

ptcpdump

eBPF-based packet analyzer that captures network traffic with automatic process, container, and Kubernetes pod metadata annotation, supporting tcpdump-compatible filtering and PcapNG output.

1.3k67724 months agoReviewed by Kitploit
View Repository

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

ptcpdump

amd64-e2e arm64-e2e Release Coveralls English | δΈ­ζ–‡

ptcpdump is a tcpdump-compatible packet analyzer powered by eBPF, automatically annotating packets with process/container/pod metadata when detectable. Inspired by jschwinger233/skbdump.

Table of Contents

  • Features
  • Installation
    • Requirements
  • Usage
    • Example commands
    • Example output
    • Running with Docker
    • Backend
    • Flags
  • Compare with tcpdump
  • Developing
    • Dependencies
    • Building
  • Related Projects
    • Flownix

Features

  • πŸ” Process/container/pod-aware packet capture.
  • πŸ“¦ Filter by: --pid (process), --pname (process name), --container-id (container), --pod-name (pod).
  • 🎯 tcpdump-compatible flags (-i, -w, -c, -s, -n, -C, -W, -A, and more).
  • πŸ“œ Supports pcap-filter(7) syntax like tcpdump.
  • 🌳 tcpdump-like output + process/container/pod context.
  • πŸ“‘ Verbose mode shows detailed metadata for processes and containers/pods.
  • πŸ’Ύ PcapNG with embedded metadata (Wireshark-ready).
  • 🌐 Cross-namespace capture (--netns).
  • πŸš€ Kernel-space BPF filtering (low overhead, reduces CPU usage).
  • ⚑ Container runtime integration (Docker, containerd).

Installation

You can download the statically linked executable for x86_64 and arm64 from the releases page.

Requirements

Linux kernel >= 5.2 (compiled with BPF and BTF support).

ptcpdump optionally requires debugfs. It has to be mounted in /sys/kernel/debug. In case the folder is empty, it can be mounted with:

mount -t debugfs none /sys/kernel/debug

The following kernel configuration is required. Building as Modules is also possible.

OptionBackendNote
CONFIG_BPF=ybothRequired
CONFIG_BPF_SYSCALL=ybothRequired
CONFIG_DEBUG_INFO=ybothRequired
CONFIG_DEBUG_INFO_BTF=ybothRequired
CONFIG_KPROBES=ybothRequired
CONFIG_KPROBE_EVENTS=ybothRequired
CONFIG_TRACEPOINTS=ybothRequired
CONFIG_PERF_EVENTS=ybothRequired
CONFIG_NET=ybothRequired
CONFIG_NET_SCHED=ytcRequired
CONFIG_NET_CLS_BPF=ytcRequired
CONFIG_NET_ACT_BPF=ytcRequired
CONFIG_NET_SCH_INGRESS=ytcRequired
CONFIG_CGROUPS=ycgroup-skbRequired
CONFIG_CGROUP_BPF=ycgroup-skbRequired
CONFIG_FILTER=ysocket-filterRequired
CONFIG_BPF_TRAMPOLINE=ytp-btfRequired
CONFIG_SECURITY=ybothOptional (Recommended)
CONFIG_BPF_TRAMPOLINE=ybothOptional (Recommended)
CONFIG_SOCK_CGROUP_DATA=ybothOptional (Recommended)
CONFIG_BPF_JIT=ybothOptional (Recommended)
CONFIG_CGROUP_BPF=ytc, tp-btf, socket-filterOptional (Recommended)
CONFIG_CGROUPS=ytc, tp-btf, socket-filterOptional (Recommended)

You can use zgrep $OPTION /proc/config.gz to validate whether an option is enabled.

πŸ”

Usage

Example commands

Filter like tcpdump:

sudo ptcpdump -i eth0 tcp
sudo ptcpdump -i eth0 -A -s 0 -n -v tcp and port 80 and host 10.10.1.1
sudo ptcpdump -i any -s 0 -n -v -C 100MB -W 3 -w test.pcapng 'tcp and port 80 and host 10.10.1.1'
sudo ptcpdump -i eth0 'tcp[tcpflags] & (tcp-syn|tcp-fin) != 0'

Multiple interfaces:

sudo ptcpdump -i eth0 -i lo

Filter by process or user:

sudo ptcpdump -i any --pid 1234 --pid 233 -f
sudo ptcpdump -i any --pname curl
sudo ptcpdump -i any --uid 1000

Capture by process via run target program:

sudo ptcpdump -i any -- curl ubuntu.com

Filter by container or pod:

sudo ptcpdump -i any --container-id 36f0310403b1
sudo ptcpdump -i any --container-name test
sudo ptcpdump -i any --pod-name test.default

Save data in PcapNG format:

sudo ptcpdump -i any -w demo.pcapng
sudo ptcpdump -i any -w - port 80 | tcpdump -n -r -
sudo ptcpdump -i any -w - port 80 | tshark -r -

Capturing interfaces in other network namespaces:

sudo ptcpdump -i lo --netns /run/netns/foo --netns /run/netns/bar
sudo ptcpdump -i any --netns /run/netns/foobar
sudo ptcpdump -i any --netns /proc/26/ns/net

πŸ”

Example output

Default:

09:32:09.718892 vethee2a302f wget.3553008 In IP 10.244.0.2.33426 > 139.178.84.217.80: Flags [S], seq 4113492822, win 64240, length 0, ParentProc [python3.834381], Container [test], Pod [test.default]
09:32:09.718941 eth0 wget.3553008 Out IP 172.19.0.2.33426 > 139.178.84.217.80: Flags [S], seq 4113492822, win 64240, length 0, ParentProc [python3.834381], Container [test], Pod [test.default]

With -q:

09:32:09.718892 vethee2a302f wget.3553008 In IP 10.244.0.2.33426 > 139.178.84.217.80: tcp 0, ParentProc [python3.834381], Container [test], Pod [test.default]
09:32:09.718941 eth0 wget.3553008 Out IP 172.19.0.2.33426 > 139.178.84.217.80: tcp 0, ParentProc [python3.834381], Container [test], Pod [test.default]

With -v:

Download Tool