Friday, May 17, 2019

Quick help with tcpdump

I know how to see all incoming traffic, filter it or see MAC addresses but I was wondering if there is a way to add geolocation to it.

Such that I would be able to see like Canada, QB or USA, CA. I find this helps me figure out a problem faster if I already have in mind who and where the packets are coming from. For example, getting the ip in reverse by knowing the location. I just need a real time view along with other info. Or perhaps a recommendation to another problem I can run side-by-side.

I prefer to do everything from the CLI.

Thanks!



No comments:

Post a Comment