Capture network traffic
The dashboard shows the last 5 days of traffic. To keep the traffic for longer, or to open it in a tool like Wireshark, record it in a PCAP file.
Start a capture
Connect to your PiRogue and run:
sudo tcpdump -i wlan0 -w $(date +%Y%m%d%H%M)_capture.pcap
Press Ctrl + C to stop. The file is named after the date and time of the start, for example 202609251430_capture.pcap.
| Part | Meaning |
|---|---|
tcpdump | The tool that records network packets |
-i wlan0 | The interface to listen to: the Wi-Fi interface of the PiRogue, the one your device is connected to |
-w <file> | Write the packets to this file, in PCAP format |
$(date +%Y%m%d%H%M) | Inserts the current date and time in the file name, so captures never overwrite each other |
wlan0 applies to a PiRogue in access point mode. In other modes, list your interfaces with ip -br link and pick the one the analyzed device uses.
Get the file on your computer
scp pi@<PiRogue IP address>:~/202609251430_capture.pcap .
Not sure how to find the IP address? See Useful commands.
Analyze it
Open the PCAP file with Wireshark. To decrypt TLS traffic from an Android app, see Mobile app analysis.
A PCAP (Packet Capture) file stores the raw network packets with their headers, payload and timestamps. It is the standard format for network troubleshooting and security investigations.