Skip to main content

Capture network traffic

The dashboard shows the last 5 days of traffic. To keep the traffic for longer, or to open it in a tool like Wireshark, record it in a PCAP file.

Start a capture​

Connect to your PiRogue and run:

Record the traffic of the Wi-Fi network into a file
sudo tcpdump -i wlan0 -w $(date +%Y%m%d%H%M)_capture.pcap

Press Ctrl + C to stop. The file is named after the date and time of the start, for example 202609251430_capture.pcap.

PartMeaning
tcpdumpThe tool that records network packets
-i wlan0The interface to listen to: the Wi-Fi interface of the PiRogue, the one your device is connected to
-w <file>Write the packets to this file, in PCAP format
$(date +%Y%m%d%H%M)Inserts the current date and time in the file name, so captures never overwrite each other
Which interface?

wlan0 applies to a PiRogue in access point mode. In other modes, list your interfaces with ip -br link and pick the one the analyzed device uses.

Get the file on your computer​

Run on your computer
scp pi@<PiRogue IP address>:~/202609251430_capture.pcap .

Not sure how to find the IP address? See Useful commands.

Analyze it​

Open the PCAP file with Wireshark. To decrypt TLS traffic from an Android app, see Mobile app analysis.

What is a PCAP?

A PCAP (Packet Capture) file stores the raw network packets with their headers, payload and timestamps. It is the standard format for network troubleshooting and security investigations.