Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
ptcpdump — 基于 eBPF 的数据包分析器,能够捕获网络流量,并自动添加进程、容器和 Kubernetes Pod 元数据注释,支持 tcpdump 兼容的过滤和 PcapNG 输出。 | Kitploit
工具/GitHubGitHub/mozillazg/ptcpdump
数据包嗅探与分析容器安全动态分析 (沙盒)网络取证取证分析网络安全数字取证云安全
GitHubmozillazg/ptcpdump

ptcpdump

基于 eBPF 的数据包分析器,能够捕获网络流量,并自动添加进程、容器和 Kubernetes Pod 元数据注释,支持 tcpdump 兼容的过滤和 PcapNG 输出。

查看仓库
1.3k67724个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

ptcpdump

amd64-e2e arm64-e2e English | 中文

ptcpdump 是一个使用 eBPF 技术实现的、类 tcpdump 的网络流程抓包工具。 它除了兼容 tcpdump 的包过滤语法和常用命令行参数外, 还提供了一个额外的特性: 在尽可能的情况下,以包注释的形式,为每个数据包流量关联发起方或接收方的进程信息。 Inspired by jschwinger233/skbdump.

Table of Contents

  • Features
  • Installation
    • Requirements
  • Usage
    • Example commands
    • Example output
    • Running with Docker
    • Backend
    • Flags
  • Compare with tcpdump
  • Developing
    • Dependencies
    • Building
  • Related Projects
    • Flownix

Features

  • 进程感知
    • 感知每个数据包流量对应的发起方或接收方的进程信息
    • 支持按进程 ID 或进程名称过滤流量
  • 容器和 Kubernetes 感知
    • 感知每个数据包流量对应的发起方或接收方的进程所属的容器和 Pod 信息
    • 支持多种容器运行时: Docker Engine 和 containerd
    • 支持按容器 ID、容器名称或 Pod 名称过滤流量
  • 支持使用 tcpdump 支持的 pcap-filter(7) 语法过滤流量
  • 直接在内核态应用过滤规则,避免在用户态应用过滤规则导致的性能问题
  • 支持以 pcap 或 PcapNG 保存捕获的流程, 可以使用 Wireshark、tcpdump、tshark 等第三方工具对保存的数据进行二次分析.
  • 以静态链接的方式编译程序,不依赖额外的系统链接库
  • 支持对指定网络命名空间下的网络接口进行抓包

Installation

你可以在 releases page 下载以静态链接方式编译的适用于 x86_64 和 arm64 架构的二进制文件。

Requirements

ptcpdump 只支持 Linux 系统,并且系统的内核版本最好 >= 5.2 (内核需要启用 BPF 和 BTF 支持)。

对于内核版本介于 4.18 ~ 5.2 之间的系统,如果系统中未提供程序依赖的内核 BTF 文件的话, ptcpdump 将自动尝试从 龙蜥 BTF 目录 和 BTFhub 下载当前系统内核版本对应的 BTF 文件。

🔝

Usage

Example commands

支持 tcpdump 支持的包过滤语法以及常用命令行参数:

sudo ptcpdump -i eth0 tcp
sudo ptcpdump -i eth0 -A -s 0 -n -v tcp and port 80 and host 10.10.1.1
sudo ptcpdump -i any -s 0 -n -v -C 100MB -W 3 -w test.pcapng 'tcp and port 80 and host 10.10.1.1'
sudo ptcpdump -i eth0 'tcp[tcpflags] & (tcp-syn|tcp-fin) != 0'

对多个网络接口进行抓包:

sudo ptcpdump -i eth0 -i lo

按进程过滤:

sudo ptcpdump -i any --pid 1234 --pid 233 -f
sudo ptcpdump -i any --pname curl

通过执行目标程序的方式进行抓包:

sudo ptcpdump -i any -- curl ubuntu.com

按容器过滤:

sudo ptcpdump -i any --container-id 36f0310403b1
sudo ptcpdump -i any --container-name test

按 Pod 过滤

sudo ptcpdump -i any --pod-name test.default

以 PcapNG 格式保存捕获的流量:

sudo ptcpdump -i any -w demo.pcapng
sudo ptcpdump -i any -w - port 80 | tcpdump -n -r -
sudo ptcpdump -i any -w - port 80 | tshark -r -

支持对其他网络命名空间下的网络接口进行抓包:

sudo ptcpdump -i lo --netns /run/netns/foo --netns /run/netns/bar
sudo ptcpdump -i any --netns /run/netns/foobar
sudo ptcpdump -i any --netns /proc/26/ns/net

🔝

Example output

默认输出:

09:32:09.718892 vethee2a302f wget.3553008 In IP 10.244.0.2.33426 > 139.178.84.217.80: Flags [S], seq 4113492822, win 64240, length 0, ParentProc [python3.834381], Container [test], Pod [test.default]
09:32:09.718941 eth0 wget.3553008 Out IP 172.19.0.2.33426 > 139.178.84.217.80: Flags [S], seq 4113492822, win 64240, length 0, ParentProc [python3.834381], Container [test], Pod [test.default]

通过 -q 参数指定不输出协议详细信息:

09:32:09.718892 vethee2a302f wget.3553008 In IP 10.244.0.2.33426 > 139.178.84.217.80: tcp 0, ParentProc [python3.834381], Container [test], Pod [test.default]
09:32:09.718941 eth0 wget.3553008 Out IP 172.19.0.2.33426 > 139.178.84.217.80: tcp 0, ParentProc [python3.834381], Container [test], Pod [test.default]

通过 -v 参数以详细方式输出:

13:44:41.529003 eth0 In IP (tos 0x4, ttl 45, id 45428, offset 0, flags [DF], proto TCP (6), length 52)
    139.178.84.217.443 > 172.19.0.2.42606: Flags [.], cksum 0x5284, seq 3173118145, ack 1385712707, win 118, options [nop,nop,TS val 134560683 ecr 1627716996], length 0
    Process (pid 553587, cmd /usr/bin/wget, args wget kernel.org)
    ParentProc (pid 553296, cmd /bin/sh, args sh)
    Container (name test, id d9028334568bf75a5a084963a8f98f78c56bba7f45f823b3780a135b71b91e95, image docker.io/library/alpine:3.18, labels {"io.cri-containerd.kind":"container","io.kubernetes.container.name":"test","io.kubernetes.pod.name":"test","io.kubernetes.pod.namespace":"default","io.kubernetes.pod.uid":"9e4bc54b-de48-4b1c-8b9e-54709f67ed0c"})
    Pod (name test, namespace default, UID 9e4bc54b-de48-4b1c-8b9e-54709f67ed0c, labels {"run":"test"}, annotations {"kubernetes.io/config.seen":"2024-07-21T12:41:00.460249620Z","kubernetes.io/config.source":"api"})

使用 --context 限制输出中的进程/容器/Pod相关上下文信息(默认显示所有上下文信息):

# --context=process
09:32:09.718892 vethee2a302f wget.3553008 In IP 10.244.0.2.33426 > 139.178.84.217.80: Flags [S], seq 4113492822, win 64240, length 0

# -v --context=process
13:44:41.529003 eth0 In IP (tos 0x4, ttl 45, id 45428, offset 0, flags [DF], proto TCP (6), length 52)
    139.178.84.217.443 > 172.19.0.2.42606: Flags [.], cksum 0x5284, seq 3173118145, ack 1385712707, win 118, options [nop,nop,TS val 134560683 ecr 1627716996], length 0
    Process (pid 553587, cmd /usr/bin/wget, args wget kernel.org)

# -v --context=process,parentproc,container,pod
# or -v --context=process --context=parentproc --context=container --context=pod
13:44:41.529003 eth0 In IP (tos 0x4, ttl 45, id 45428, offset 0, flags [DF], proto TCP (6), length 52)
    139.178.84.217.443 > 172.19.0.2.42606: Flags [.], cksum 0x5284, seq 3173118145, ack 1385712707, win 118, options [nop,nop,TS val 134560683 ecr 1627716996], length 0
    Process (pid 553587, cmd /usr/bin/wget, args wget kernel.org)
    ParentProc (pid 553296, cmd /bin/sh, args sh)
    Container (name test, id d9028334568bf75a5a084963a8f98f78c56bba7f45f823b3780a135b71b91e95, image docker.io/library/alpine:3.18, labels {"io.cri-containerd.kind":"container","io.kubernetes.container.name":"test","io.kubernetes.pod.name":"test","io.kubernetes.pod.namespace":"default","io.kubernetes.pod.uid":"9e4bc54b-de48-4b1c-8b9e-54709f67ed0c"})
    Pod (name test, namespace default, UID 9e4bc54b-de48-4b1c-8b9e-54709f67ed0c, labels {"run":"test"}, annotations {"kubernetes.io/config.seen":"2024-07-21T12:41:00.460249620Z","kubernetes.io/config.source":"api"})

通过 -A 参数以 ASCII 格式输出:

14:44:34.457504 ens33 curl.205562 Out IP 10.0.2.15.39984 > 139.178.84.217.80: Flags [P.], seq 2722472188:2722472262, ack 892036871, win 64240, length 74, ParentProc [bash.180205]
E..r.,@[email protected].
.....T..0.P.E..5+g.P.......GET / HTTP/1.1
Host: kernel.org
User-Agent: curl/7.81.0
Accept: */*

通过 -x 参数以 16 进制格式输出:

14:44:34.457504 ens33 curl.205562 Out IP 10.0.2.15.39984 > 139.178.84.217.80: Flags [P.], seq 2722472188:2722472262, ack 892036871, win 64240, length 74, ParentProc [bash.180205]
        0x0000:  4500 0072 de2c 4000 4006 6fbf 0a00 020f
        0x0010:  8bb2 54d9 9c30 0050 a245 a0fc 352b 6707
        0x0020:  5018 faf0 ecfe 0000 4745 5420 2f20 4854
        0x0030:  5450 2f31 2e31 0d0a 486f 7374 3a20 6b65
        0x0040:  726e 656c 2e6f 7267 0d0a 5573 6572 2d41
        0x0050:  6765 6e74 3a20 6375 726c 2f37 2e38 312e
        0x0060:  300d 0a41 6363 6570 743a 202a 2f2a 0d0a
        0x0070:  0d0a

通过 -X 参数以 16 进制和 ASCII 格式输出:

下载工具