#tcpdump
New on the blog: what happens to detection when AI agents run curl, tcpdump and Python scripts all day long, just like attackers do. A look at detection fidelity in the age of AI agents living off the land, and a roadmap for defenders.

jvehent.org/2026/09/22/d...
Detection fidelity in the age of AI agents living off the land
Now that we’re all using coding agents and AI agents for our everyday tasks, our systems are filling up with an enormous amount of noise, and nearly all of it lives off the land. That noise is eroding...
jvehent.org
September 26, 2026 at 6:02 PM
nsenter -t PID -n swaps your net namespace to a target process's stack via setns(2). Run tcpdump on its interfaces, routes, and iptables rules. Works in K8s and https://www.valtersit.com/vault/enter-a-target-process-network-namespace-with-nsenter-for-li-1a021a/

#linux #nsenter #network-namespace
Enter a target process network namespace with nsenter for live packet capture
www.valtersit.com
September 24, 2026 at 2:00 PM
W dzisiejszym tutorialu z cyklu Porady Admina zajmiemy się programem tcpdump. Tcpdump to analizator ruchu sieciowego dla wiersza poleceń. Program umożliwia zapisywanie ruchu... linuxiarze.pl/porady-admin... #network #linux #admin
September 24, 2026 at 11:55 AM
Rolling tcpdump captures: full packets, interface/protocol filters, ring-buffer file size limits for continuous forensic PCAP rotation. https://www.valtersit.com/vault/stream-rolling-forensic-packet-capture-with-filtered-size-li-2103f3/ #tcpdump #security #ValtersIT
Stream Rolling Forensic Packet Capture with Filtered Size Limits via tcpdump
www.valtersit.com
September 24, 2026 at 5:00 AM
Packet loss at 3am, tcpdump shows SYN with no SYN-ACK, and no agent installed. eBPF tools like bpftrace and tcpdrop ship in the kernel, so you can trace the drop in minutes. Guide: https://www.valtersit.com/guides/linux/ebpf-network-observability-zero-install-kernel-tools/ #eBPF #Linux #Sysadmin
September 23, 2026 at 9:30 AM
September 22, 2026 at 11:54 PM
A few tcpdump commands can tell you a lot about what is actually happening on your network 😎👇

Find high-res pdf ebooks with all my networking related infographics at study-notes.org

#cybersecurity #infosec #linux #devops #sysadmin
September 22, 2026 at 2:19 PM
Reached for tcpdump for the first time in 9 or 10 months. Longest such gap in years. (Odd issues on my home network turned out to be due to two nodes claiming the same ipv6 address, despite distinct ipv4 addresses. Only caused marginal problems because so much stuff tolerates broken ipv6.)
September 18, 2026 at 3:28 PM
CVE-2026-75166: Insecure permission in MBS-Solutions X-Serie Gateway (V6_00_05) lets low-priv user run tcpdump as root, leading to RCE via -z flag. CVSS: N/A. Patch unknown—assume vulnerable. Restrict access & monitor now. https://www.valtersit.com/cve/CVE-2026-75166/ #CVE #infos
September 13, 2026 at 2:50 AM
Linux Snippets #12: tcpdump Without Capturing the Entire Internet
Capture everything and inspect it later' sounds reassuringly forensic until the PCAP consu […]
Original post on social.data.coop
social.data.coop
September 11, 2026 at 10:23 AM
Your network is broken. Now what? 👀🌐

The right debugging tool can save you hours of guesswork.

Here’s a practical list for checking traffic, DNS, connections, and more:
👉 reliasoftware.com/blog/network...

#Networking #Debugging #DevTools
Top 7 Common Network Debugging Tools for DevOps Experts
tcpdump, netstat, dig, docker network, iperf, conntrack, and ip route are 7 vital network debugging tools for DevOps experts. Learn their commands and best practices.
reliasoftware.com
September 10, 2026 at 11:01 AM
Somehow, I've migrated from "running tcpdump" to "reading the NFS RFCs". This is surely not a sign of descent into madness.
September 9, 2026 at 1:43 PM
Project GhostNet: Build a Self-Contained Network Threat Detection, SIEM, and Beacon-Huntin

Build Project GhostNet, an advanced C2 beacon detection lab using Suricata, TCPDump, Elasticsearch, Kibana and Python for…

https://thecybersecguru.com/projects/project-ghostnet-c2-beacon-detection-lab/
September 9, 2026 at 1:40 PM
6 free tools to read every packet on a network: Wireshark, tcpdump, termshark, ngrep, Zeek, and Arkime.

Logs tell you what a system chose to record. Packets tell you what actually crossed the wire.

Free web-book: https://app.stationx.net/book
September 9, 2026 at 12:02 PM
tcpdump can't tell you why packets drop silently. Debug production network spikes with built-in eBPF tools like bpftrace and tcpdrop—zero agents required. #eBPF #Linux #Sysadmin

https://www.valtersit.com/guides/linux/ebpf-network-observability-zero-install-kernel-tools/
September 7, 2026 at 2:00 PM
I finally figured out how to match veth endpoints on the host to #Docker containers on #Linux by mapping network namespaces.

Here's a gist if you need to figure out which veth device to run tcpdump against.
gist.github.com/amf3/ca6b910...
How do I map a VETH pair to a Docker Container?
How do I map a VETH pair to a Docker Container? GitHub Gist: instantly share code, notes, and snippets.
gist.github.com
August 30, 2026 at 2:41 PM
Network Security Monitoring and Traffic Analysis on Linux

Inspect network connection states. Run targeted packet captures using tcpdump, audit socket stats, and detect anomalous port scans.
Network Security Monitoring and Traffic Analysis on Linux
Inspect network connection states. Run targeted packet captures using tcpdump, audit socket stats, and detect anomalous port scans.
mike.co.ke
August 28, 2026 at 6:00 AM
every Linux networking tool I know

permalink: https://wizardzines.com/comics/every-linux-networking-tool-i-know/

from our zine Bite Size Networking!: https://wizardzines.com/zines/bite-size-networking/
August 26, 2026 at 8:02 PM
tcpdump for DevOps: Read a TCP Handshake and Stop Guessing dev.to/jjoyneriv/tc...
tcpdump for DevOps: Read a TCP Handshake and Stop Guessing
When a service "can't connect," the app logs and the network rarely tell the same story. tcpdump...
dev.to
August 25, 2026 at 8:14 PM
Linux server load suddenly spiked? 🚨 Don't guess, diagnose it!

Learn how to use standard CLI tools (iftop, sar, ss) to hunt down DDoS attacks, TCP state exhaustion & HTTP floods in real-time. 💻🔍

Read the full step-by-step sysadmin guide here 👇
www.migservers.com/tutorials/ho...

#Linux #DDoS
How to Detect a DDoS Attack on Linux (CLI Tutorial)
Is your Linux server under attack? Learn how to detect DDoS attacks using command-line tools like netstat, iftop, and tcpdump in this quick tutorial.
www.migservers.com
August 21, 2026 at 5:46 AM