A Guide to Network Packet Capture and Analysis with Tshark on Linux: Investigating Anomalous Traffic and Detecting Attacks from the CLI

Security tutorial - IT technology blog
Security tutorial - IT technology blog

When Your Server Suddenly Overloads: Where Do You Look?

In the middle of the night, Telegram alert notifications ring continuously. Server CPU hits 100%, network bandwidth is fully saturated, and application responses become abnormally sluggish. You quickly SSH into the server, run netstat, and see thousands of TCP connections opening in rapid succession.

On a personal workstation, you can easily launch Wireshark to filter packets through a graphical interface. But on a production server accessed via SSH, you are confined to a plain monochrome terminal. Relying on tcpdump floods your screen with raw logs moving as fast as a waterfall, making it cumbersome to dissect application-layer (L7) details. This is precisely where Tshark shines.

I once spent nearly three hours diagnosing a sophisticated SSH brute-force incident across a web server cluster. Ever since that painful lesson, Tshark has been the very first tool I install on every managed server.

What Is Tshark and Why Replace tcpdump with It?

Put simply, Tshark is the command-line interface (CLI) counterpart of Wireshark. Both share the exact same protocol dissection libraries. Any protocol Wireshark can analyze, Tshark can dissect with equal fluency.

While tcpdump is ubiquitous and pre-installed on most Linux distributions, Tshark stands out across three critical areas:

  • Deep Application-Layer (Layer 7) Inspection: Tshark natively extracts fields from HTTP headers, DNS queries, TLS Handshake certificates, or SSH payloads without requiring complex string-parsing scripts.
  • Extremely Powerful Display Filters: You can reuse the full, familiar syntax of Wireshark, such as http.request.method == "POST" or dns.flags.response == 0.
  • Customizable Data Extraction: Easily isolate fields like source IP, HTTP status codes, or User-Agent headers into formatted columns to pipe directly into grep, awk, and sort.

Hands-on: Capturing and Investigating Packets with Tshark

1. Installing Tshark on Linux

On Ubuntu or Debian, install it quickly via APT:

sudo apt update
sudo apt install -y tshark

During the installation process, the system prompts whether non-root users should be allowed to capture packets. Select Yes, then add your current user to the wireshark group so you do not have to prepend sudo to every command:

sudo usermod -aG wireshark $USER
# Log out and log back in via SSH for the new permissions to take effect

2. Identifying Network Interfaces and Capturing Live Traffic

First, list the available active network interfaces:

tshark -D

The system displays interfaces such as 1. eth0, 2. lo (loopback). Assuming your primary outbound network interface is eth0, start monitoring live traffic:

tshark -i eth0

The screen streams live packets traversing the network interface. Press Ctrl + C whenever you want to stop.

3. Filtering Data Fields with the -T fields Option

Instead of scanning lengthy raw log streams, the -T fields option lets you isolate only the necessary data points:

tshark -i eth0 -T fields -e ip.src -e ip.dst -e _ws.col.Protocol -e _ws.col.Info

The command above prints four distinct columns: Source IP, Destination IP, Protocol, and Packet Summary Information, cleanly separated by tabs.

4. Scenario 1: Detecting SYN Port Scans

When an attacker uses Nmap to scan your server ports (in SYN scan mode), they flood TCP SYN packets without returning ACK packets to complete the three-way handshake. You can isolate these specific packets:

tshark -i eth0 -Y "tcp.flags.syn == 1 and tcp.flags.ack == 0" -T fields -e ip.src -e tcp.dstport

If an unknown IP address continuously sends packets targeting dozens of different ports (21, 22, 80, 443, 3306, 8080…) within just 1–2 seconds, your server is almost certainly undergoing reconnaissance for vulnerabilities.

5. Scenario 2: Tracing SSH Brute-Force Attacks

When an attacker runs an automated password-guessing tool against SSH (such as Hydra), connection attempts to port 22 spike abruptly. The command below captures and aggregates the top IP addresses connecting to port 22 over a 20-second window:

tshark -i eth0 -a duration:20 -Y "tcp.dstport == 22 and tcp.flags.syn == 1" -T fields -e ip.src | sort | uniq -c | sort -nr

Breakdown of each parameter:

  • -a duration:20: Automatically terminates after 20 seconds.
  • -Y "tcp.dstport == 22 and tcp.flags.syn == 1": Filters only TCP handshake initialization packets hitting the SSH port.
  • sort | uniq -c | sort -nr: Groups and sorts IP addresses in descending order of connection frequency.

If you spot an IP initiating 50–100 requests within 20 seconds, you can immediately block it with iptables -A INPUT -s <ATTACKER_IP> -j DROP or ufw deny from <ATTACKER_IP>.

6. Scenario 3: Detecting Data Exfiltration via DNS (DNS Tunneling)

Malware and botnets frequently exploit DNS queries to covertly exfiltrate data or communicate with Command and Control (C2) servers, as UDP port 53 is rarely blocked by firewalls. You can monitor every domain name resolution requested by the server:

tshark -i eth0 -Y "dns.flags.response == 0" -T fields -e ip.src -e dns.qry.name

If you notice subdomains featuring randomized strings or abnormally long Base64-encoded strings (for example: dGVzdC1kYXRh.malicious-domain.com), there is a high probability the server has been compromised and is leaking data behind the scenes.

7. Capturing Traffic to a .pcap File for In-Depth Analysis

During an active security incident, the safest approach is dumping raw network traffic directly into a .pcap file before performing thorough post-mortem analysis:

# Capture exactly 10,000 packets and write to incident.pcap
sudo tshark -i eth0 -c 10000 -w /tmp/incident.pcap

You can then perform offline analysis on this file directly on the server at any time:

# Quickly filter HTTP requests returning 4xx or 5xx error codes
tshark -r /tmp/incident.pcap -Y "http.response.code >= 400" -T fields -e ip.src -e http.response.code -e http.request.uri

Conclusion

Tshark serves as an indispensable magnifying glass right inside your Linux terminal. You don’t need to transfer gigabytes of packet dumps back to your local machine just to filter a few log lines in Wireshark. Once you master Tshark’s core filters, you can rapidly isolate root causes and proactively defend your servers against unexpected attacks.

Share: