{"id":443,"date":"2026-05-25T17:46:52","date_gmt":"2026-05-25T15:46:52","guid":{"rendered":"https:\/\/eryann.fr\/?p=443"},"modified":"2026-05-25T17:46:54","modified_gmt":"2026-05-25T15:46:54","slug":"fiche-analyse-de-trafic-avec-tcpdump","status":"publish","type":"post","link":"https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/","title":{"rendered":"Fiche analyse de trafic avec tcpdump"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">1. Introduction<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Dans un BTS CIEL ou SIO, tu dois rapidement apprendre \u00e0 diagnostiquer un probl\u00e8me r\u00e9seau, v\u00e9rifier un flux applicatif ou analyser des communications suspectes. <code>tcpdump<\/code> fait partie des outils incontournables pour ce travail.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cet utilitaire fonctionne directement en ligne de commande. Il capture les paquets r\u00e9seau qui transitent sur une interface et permet ensuite d\u2019analyser pr\u00e9cis\u00e9ment les \u00e9changes entre machines, protocoles et applications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tu peux utiliser <code>tcpdump<\/code> pour :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>v\u00e9rifier qu\u2019un serveur \u00e9coute correctement ;<\/li>\n\n\n\n<li>analyser une connexion HTTP, HTTPS ou DNS ;<\/li>\n\n\n\n<li>d\u00e9tecter une anomalie r\u00e9seau ;<\/li>\n\n\n\n<li>comprendre un \u00e9change TCP ;<\/li>\n\n\n\n<li>diagnostiquer un probl\u00e8me de pare-feu ;<\/li>\n\n\n\n<li>contr\u00f4ler le trafic MQTT, SSH, FTP ou ICMP ;<\/li>\n\n\n\n<li>produire des captures compatibles avec Wireshark.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Dans cette fiche, tu vas apprendre :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>installer <code>tcpdump<\/code> ;<\/li>\n\n\n\n<li>capturer du trafic ;<\/li>\n\n\n\n<li>filtrer les paquets ;<\/li>\n\n\n\n<li>analyser plusieurs protocoles ;<\/li>\n\n\n\n<li>cr\u00e9er des filtres simples et avanc\u00e9s ;<\/li>\n\n\n\n<li>sauvegarder les captures ;<\/li>\n\n\n\n<li>utiliser les bons r\u00e9flexes de s\u00e9curit\u00e9.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">2. Sommaire<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Introduction<\/li>\n\n\n\n<li>Sommaire<\/li>\n\n\n\n<li>Installation de tcpdump<\/li>\n\n\n\n<li>Fonctionnement g\u00e9n\u00e9ral<\/li>\n\n\n\n<li>Identifier les interfaces r\u00e9seau<\/li>\n\n\n\n<li>Capturer du trafic simple<\/li>\n\n\n\n<li>Analyse des principaux protocoles<\/li>\n\n\n\n<li>Filtres simples<\/li>\n\n\n\n<li>Filtres avanc\u00e9s<\/li>\n\n\n\n<li>Sauvegarder et relire une capture<\/li>\n\n\n\n<li>Pare-feu et ports utiles<\/li>\n\n\n\n<li>Fichiers importants<\/li>\n\n\n\n<li>Synth\u00e8se Markdown pour ta fiche bristol<\/li>\n\n\n\n<li>Bloc de configuration complet<\/li>\n\n\n\n<li>Commandes de d\u00e9pannage<\/li>\n\n\n\n<li>Logs et analyse<\/li>\n\n\n\n<li>Erreurs fr\u00e9quentes<\/li>\n\n\n\n<li>Bonnes pratiques de s\u00e9curit\u00e9<\/li>\n\n\n\n<li>Pour aller plus loin<\/li>\n\n\n\n<li>Liens utiles et documentation<\/li>\n\n\n\n<li>Id\u00e9es de TP<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">3. Installation de tcpdump<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Sous Debian 13 et Ubuntu 26.04 :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo apt update<br>sudo apt install tcpdump<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Explication des commandes<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>apt update<\/code> met \u00e0 jour la liste des paquets disponibles.<\/li>\n\n\n\n<li><code>apt install tcpdump<\/code> installe l\u2019outil.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Tu peux v\u00e9rifier l\u2019installation avec :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>tcpdump --version<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">4. Fonctionnement g\u00e9n\u00e9ral<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>tcpdump<\/code> \u00e9coute une interface r\u00e9seau et affiche les paquets captur\u00e9s.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Syntaxe g\u00e9n\u00e9rale :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump &#91;options] &#91;filtres]<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Pourquoi utiliser sudo ?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">La capture r\u00e9seau n\u00e9cessite l\u2019acc\u00e8s bas niveau aux interfaces r\u00e9seau. Sans privil\u00e8ges \u00e9lev\u00e9s, Linux refuse g\u00e9n\u00e9ralement l\u2019op\u00e9ration.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">5. Identifier les interfaces r\u00e9seau<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Avant de capturer du trafic, tu dois conna\u00eetre le nom de l\u2019interface r\u00e9seau.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Commande recommand\u00e9e :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ip a<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Exemple :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>2: ens18: &lt;BROADCAST,MULTICAST,UP,LOWER_UP&gt;<br>3: lo: &lt;LOOPBACK,UP,LOWER_UP&gt;<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Ici :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>ens18<\/code> correspond \u00e0 la carte r\u00e9seau principale ;<\/li>\n\n\n\n<li><code>lo<\/code> repr\u00e9sente l\u2019interface locale (localhost).<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Tu peux aussi demander directement \u00e0 tcpdump :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>tcpdump -D<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Explication des options<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>-D<\/code> : liste les interfaces disponibles.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">6. Capturer du trafic simple<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Capturer tout le trafic<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Explication<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>-i ens18<\/code> : \u00e9coute l\u2019interface <code>ens18<\/code>.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Capturer uniquement 10 paquets<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 -c 10<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Explication<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>-c 10<\/code> : arr\u00eate la capture apr\u00e8s 10 paquets.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Afficher les adresses IP sans r\u00e9solution DNS<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 -n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Pourquoi utiliser <code>-n<\/code> ?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Sans cette option, tcpdump tente de r\u00e9soudre les noms DNS. Cela ralentit l\u2019analyse et ajoute du bruit.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Afficher aussi les ports<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 -nn<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Diff\u00e9rence entre <code>-n<\/code> et <code>-nn<\/code><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>-n<\/code> : d\u00e9sactive la r\u00e9solution DNS.<\/li>\n\n\n\n<li><code>-nn<\/code> : d\u00e9sactive aussi la r\u00e9solution des services r\u00e9seau.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">7. Analyse des principaux protocoles<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">7.1 Analyse ICMP (ping)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Commande :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 icmp<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Teste ensuite :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ping 8.8.8.8<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Tu verras :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>ICMP echo request<br>ICMP echo reply<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Utilit\u00e9<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>diagnostic r\u00e9seau ;<\/li>\n\n\n\n<li>test de connectivit\u00e9 ;<\/li>\n\n\n\n<li>d\u00e9tection d\u2019h\u00f4tes accessibles.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7.2 Analyse HTTP<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Le protocole HTTP utilise le port 80.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 port 80<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Tu peux ensuite ouvrir un site HTTP.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Cas concret<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Diagnostic d\u2019un serveur web Apache ou Nginx.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7.3 Analyse HTTPS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">HTTPS utilise le port 443.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 port 443<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Important<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Le contenu reste chiffr\u00e9. Tu vois :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>les IP ;<\/li>\n\n\n\n<li>les ports ;<\/li>\n\n\n\n<li>les \u00e9changes TLS ;<\/li>\n\n\n\n<li>la n\u00e9gociation SSL\/TLS.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7.4 Analyse DNS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Le DNS utilise principalement le port 53.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 port 53<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Teste ensuite :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>nslookup debian.org<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Ce que tu peux observer<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>requ\u00eates DNS ;<\/li>\n\n\n\n<li>r\u00e9ponses DNS ;<\/li>\n\n\n\n<li>serveurs utilis\u00e9s ;<\/li>\n\n\n\n<li>temps de r\u00e9ponse.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7.5 Analyse SSH<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">SSH utilise le port 22.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 port 22<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Utilit\u00e9<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>v\u00e9rifier une connexion SSH ;<\/li>\n\n\n\n<li>diagnostiquer un blocage pare-feu ;<\/li>\n\n\n\n<li>confirmer une authentification r\u00e9seau.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">7.6 Analyse MQTT<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">MQTT utilise souvent :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>1883 : MQTT non chiffr\u00e9 ;<\/li>\n\n\n\n<li>8883 : MQTT TLS.<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 port 1883<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">8. Filtres simples<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">8.1 Filtrer une IP source<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 src host 192.168.1.10<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">8.2 Filtrer une IP destination<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 dst host 192.168.1.20<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">8.3 Filtrer un r\u00e9seau<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 net 192.168.1.0\/24<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">8.4 Filtrer un protocole TCP<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 tcp<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">8.5 Filtrer UDP<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 udp<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">8.6 Filtrer plusieurs ports<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 port 80 or port 443<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">8.7 Exclure un trafic<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 not port 22<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">9. Filtres avanc\u00e9s<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">9.1 Combiner plusieurs conditions<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 host 192.168.1.10 and port 443<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Ce filtre signifie<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>trafic li\u00e9 \u00e0 l\u2019h\u00f4te <code>192.168.1.10<\/code><\/li>\n\n\n\n<li>ET utilisant le port 443.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">9.2 Capturer uniquement les SYN TCP<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 'tcp&#91;tcpflags] &amp; tcp-syn != 0'<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Utilit\u00e9<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">D\u00e9tection :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>nouvelles connexions TCP ;<\/li>\n\n\n\n<li>scans r\u00e9seau ;<\/li>\n\n\n\n<li>reconnaissance Nmap.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">9.3 Capturer les paquets avec donn\u00e9es<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 'tcp&#91;((tcp&#91;12] &amp; 0xf0) &gt;&gt; 2):4] != 0'<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Utilit\u00e9<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">\u00c9viter les paquets de contr\u00f4le TCP sans payload.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">9.4 Filtrer un \u00e9change entre deux machines<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 host 192.168.1.10 and host 192.168.1.20<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">9.5 Capturer un trafic HTTP pr\u00e9cis<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 -A port 80<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Explication<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>-A<\/code> affiche le contenu ASCII.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Tu peux parfois voir :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>requ\u00eates GET ;<\/li>\n\n\n\n<li>User-Agent ;<\/li>\n\n\n\n<li>Host ;<\/li>\n\n\n\n<li>cookies.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">9.6 Voir le contenu HEXA et ASCII<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 -X port 80<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Explication<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>-X<\/code> affiche :\n<ul class=\"wp-block-list\">\n<li>hexad\u00e9cimal ;<\/li>\n\n\n\n<li>ASCII.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Tr\u00e8s utile en forensic ou cybers\u00e9curit\u00e9.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">10. Sauvegarder et relire une capture<\/h2>\n\n\n\n<h2 class=\"wp-block-heading\">10.1 Sauvegarder une capture<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 -w capture.pcap<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Explication<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>-w<\/code> \u00e9crit dans un fichier PCAP.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">10.2 Lire une capture<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>tcpdump -r capture.pcap<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Explication<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>-r<\/code> relit un fichier.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">10.3 Ouvrir avec Wireshark<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>wireshark capture.pcap<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">11. Pare-feu et ports utiles<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Service<\/th><th>Port<\/th><th>Protocole<\/th><\/tr><\/thead><tbody><tr><td>HTTP<\/td><td>80<\/td><td>TCP<\/td><\/tr><tr><td>HTTPS<\/td><td>443<\/td><td>TCP<\/td><\/tr><tr><td>DNS<\/td><td>53<\/td><td>UDP\/TCP<\/td><\/tr><tr><td>SSH<\/td><td>22<\/td><td>TCP<\/td><\/tr><tr><td>MQTT<\/td><td>1883<\/td><td>TCP<\/td><\/tr><tr><td>MQTT TLS<\/td><td>8883<\/td><td>TCP<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Exemple UFW pour SSH<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo ufw allow 22\/tcp<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Exemple pour MQTT<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo ufw allow 1883\/tcp<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">V\u00e9rifier les r\u00e8gles<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo ufw status verbose<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">12. Fichiers importants<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code>\/etc\/ufw\/<br>\/var\/log\/ufw.log<br>\/etc\/services<br>\/usr\/sbin\/tcpdump<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Arborescence utile<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>\/etc\/<br>\u251c\u2500\u2500 ufw\/<br>\u2502   \u251c\u2500\u2500 before.rules<br>\u2502   \u251c\u2500\u2500 after.rules<br>\u2502   \u2514\u2500\u2500 user.rules<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">13. Synth\u00e8se Markdown pour ta fiche bristol<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code># TCPDUMP<br><br>## Installation<br>sudo apt install tcpdump<br><br>## Interfaces<br>ip a<br>tcpdump -D<br><br>## Capture simple<br>sudo tcpdump -i ens18<br><br>## Sans r\u00e9solution DNS<br>sudo tcpdump -i ens18 -nn<br><br>## Limiter le nombre de paquets<br>sudo tcpdump -i ens18 -c 20<br><br>## Filtrer un port<br>sudo tcpdump -i ens18 port 80<br><br>## Filtrer SSH<br>sudo tcpdump -i ens18 port 22<br><br>## Filtrer DNS<br>sudo tcpdump -i ens18 port 53<br><br>## Filtrer une IP<br>sudo tcpdump -i ens18 host 192.168.1.10<br><br>## Filtre complexe<br>sudo tcpdump -i ens18 host 192.168.1.10 and port 443<br><br>## Sauvegarde<br>sudo tcpdump -i ens18 -w capture.pcap<br><br>## Lecture capture<br>tcpdump -r capture.pcap<br><br>## Affichage ASCII<br>sudo tcpdump -A port 80<br><br>## Affichage HEXA<br>sudo tcpdump -X port 80<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">14. Bloc de configuration complet<\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code># Liste des interfaces r\u00e9seau<br>tcpdump -D<br><br># Capture compl\u00e8te sur l'interface principale<br>sudo tcpdump -i ens18 -nn<br><br># Capture limit\u00e9e \u00e0 50 paquets<br>sudo tcpdump -i ens18 -nn -c 50<br><br># Capture HTTP et HTTPS<br>sudo tcpdump -i ens18 '(port 80 or port 443)'<br><br># Capture DNS<br>sudo tcpdump -i ens18 udp port 53<br><br># Capture SSH<br>sudo tcpdump -i ens18 tcp port 22<br><br># Capture MQTT<br>sudo tcpdump -i ens18 tcp port 1883<br><br># Capture d'un h\u00f4te sp\u00e9cifique<br>sudo tcpdump -i ens18 host 192.168.1.10<br><br># Capture r\u00e9seau local<br>sudo tcpdump -i ens18 net 192.168.1.0\/24<br><br># Capture avec affichage ASCII<br>sudo tcpdump -i ens18 -A port 80<br><br># Capture avec affichage HEXA<br>sudo tcpdump -i ens18 -X port 80<br><br># Sauvegarde dans un fichier PCAP<br>sudo tcpdump -i ens18 -w analyse.pcap<br><br># Lecture d'une capture<br>tcpdump -r analyse.pcap<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">15. Commandes de d\u00e9pannage<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">V\u00e9rifier les interfaces r\u00e9seau<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>ip a<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">V\u00e9rifier les connexions actives<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>ss -tulpn<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Explication<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>-t<\/code> : TCP<\/li>\n\n\n\n<li><code>-u<\/code> : UDP<\/li>\n\n\n\n<li><code>-l<\/code> : sockets en \u00e9coute<\/li>\n\n\n\n<li><code>-p<\/code> : processus associ\u00e9s<\/li>\n\n\n\n<li><code>-n<\/code> : affichage num\u00e9rique<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">V\u00e9rifier les r\u00e8gles pare-feu<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo ufw status numbered<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">V\u00e9rifier les routes r\u00e9seau<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>ip route<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Tester DNS<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>dig debian.org<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">V\u00e9rifier une connexion TCP<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>nc -vz 192.168.1.20 443<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\">16. Logs et analyse<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>tcpdump<\/code> ne produit pas de logs permanents par d\u00e9faut. Tu dois sauvegarder les captures.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">G\u00e9n\u00e9rer une capture exploitable<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump -i ens18 -w incident.pcap<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Lire ensuite avec :<\/h3>\n\n\n\n<pre class=\"wp-block-code\"><code>tcpdump -r incident.pcap<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">ou :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>wireshark incident.pcap<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Ce que tu peux analyser<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>scans r\u00e9seau ;<\/li>\n\n\n\n<li>connexions suspectes ;<\/li>\n\n\n\n<li>erreurs TCP ;<\/li>\n\n\n\n<li>retransmissions ;<\/li>\n\n\n\n<li>DNS anormal ;<\/li>\n\n\n\n<li>flux non chiffr\u00e9s ;<\/li>\n\n\n\n<li>trafic IoT ;<\/li>\n\n\n\n<li>requ\u00eates HTTP.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">17. Erreurs fr\u00e9quentes<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Permission denied<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Cause :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>absence de privil\u00e8ges root.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Solution :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>sudo tcpdump<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Mauvaise interface r\u00e9seau<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Cause :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>interface inexistante.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Solution :<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>tcpdump -D<\/code><\/pre>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Aucun paquet affich\u00e9<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Causes possibles :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>mauvais filtre ;<\/li>\n\n\n\n<li>aucun trafic ;<\/li>\n\n\n\n<li>mauvaise interface ;<\/li>\n\n\n\n<li>pare-feu.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">Capture trop volumineuse<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Solution :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>ajouter des filtres ;<\/li>\n\n\n\n<li>limiter avec <code>-c<\/code> ;<\/li>\n\n\n\n<li>utiliser <code>host<\/code>, <code>port<\/code> ou <code>net<\/code>.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">18. Bonnes pratiques de s\u00e9curit\u00e9<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u00c9vite de capturer inutilement tout le r\u00e9seau.<\/li>\n\n\n\n<li>Prot\u00e8ge les fichiers <code>.pcap<\/code>.<\/li>\n\n\n\n<li>Supprime les captures sensibles apr\u00e8s analyse.<\/li>\n\n\n\n<li>Utilise HTTPS et TLS pour limiter les donn\u00e9es lisibles.<\/li>\n\n\n\n<li>Analyse les captures sur une machine s\u00e9curis\u00e9e.<\/li>\n\n\n\n<li>Ne capture pas de donn\u00e9es sans autorisation.<\/li>\n\n\n\n<li>Filtre au maximum pour r\u00e9duire l\u2019exposition des donn\u00e9es.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">19. Pour aller plus loin<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Tu peux approfondir :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Wireshark ;<\/li>\n\n\n\n<li>analyse TLS ;<\/li>\n\n\n\n<li>forensic r\u00e9seau ;<\/li>\n\n\n\n<li>d\u00e9tection d\u2019intrusion ;<\/li>\n\n\n\n<li>Suricata ;<\/li>\n\n\n\n<li>Zeek ;<\/li>\n\n\n\n<li>NetFlow ;<\/li>\n\n\n\n<li>analyse MQTT IoT ;<\/li>\n\n\n\n<li>captures VLAN ;<\/li>\n\n\n\n<li>IPv6 ;<\/li>\n\n\n\n<li>s\u00e9curit\u00e9 DNS.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">20. Liens utiles et documentation<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Documentation officielle tcpdump<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.tcpdump.org\/manpages\/tcpdump.1.html\">https:\/\/www.tcpdump.org\/manpages\/tcpdump.1.html<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Documentation officielle compl\u00e8te des options et filtres BPF.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Documentation Debian sur tcpdump<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/packages.debian.org\/bookworm\/tcpdump\">https:\/\/packages.debian.org\/bookworm\/tcpdump<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Permet de consulter les versions Debian et les d\u00e9pendances.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Documentation Ubuntu tcpdump<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/manpages.ubuntu.com\/manpages\/noble\/man8\/tcpdump.8.html\">https:\/\/manpages.ubuntu.com\/manpages\/noble\/man8\/tcpdump.8.html<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Version adapt\u00e9e aux syst\u00e8mes Ubuntu r\u00e9cents.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">RFC ICMP<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc792\">https:\/\/datatracker.ietf.org\/doc\/html\/rfc792<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">R\u00e9f\u00e9rence officielle du protocole ICMP.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">RFC DNS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/datatracker.ietf.org\/doc\/html\/rfc1035\">https:\/\/datatracker.ietf.org\/doc\/html\/rfc1035<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Documentation officielle DNS.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">OpenClassrooms \u2014 Comprendre les r\u00e9seaux TCP\/IP<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/openclassrooms.com\/fr\/courses\/7170496-initiez-vous-aux-reseaux-tcp-ip\">https:\/\/openclassrooms.com\/fr\/courses\/7170496-initiez-vous-aux-reseaux-tcp-ip<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tr\u00e8s bon cours d\u2019introduction r\u00e9seau.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">OpenClassrooms \u2014 S\u00e9curisez votre r\u00e9seau<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/openclassrooms.com\/fr\/courses\/1750566-securisez-votre-reseau-grace-aux-vpn-et-firewall\">https:\/\/openclassrooms.com\/fr\/courses\/1750566-securisez-votre-reseau-grace-aux-vpn-et-firewall<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Compl\u00e8te parfaitement l\u2019analyse r\u00e9seau.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">21. Id\u00e9es de TP<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">TP 1 \u2014 Analyse HTTP<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Objectif :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>capturer une requ\u00eate HTTP ;<\/li>\n\n\n\n<li>identifier :\n<ul class=\"wp-block-list\">\n<li>m\u00e9thode ;<\/li>\n\n\n\n<li>User-Agent ;<\/li>\n\n\n\n<li>Host.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">TP 2 \u2014 Analyse DNS<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Objectif :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>capturer plusieurs requ\u00eates DNS ;<\/li>\n\n\n\n<li>identifier les serveurs utilis\u00e9s.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">TP 3 \u2014 Diagnostic SSH<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Objectif :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>v\u00e9rifier une connexion SSH ;<\/li>\n\n\n\n<li>identifier :\n<ul class=\"wp-block-list\">\n<li>SYN ;<\/li>\n\n\n\n<li>SYN-ACK ;<\/li>\n\n\n\n<li>ACK.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">TP 4 \u2014 Analyse MQTT<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Objectif :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>capturer le trafic MQTT ;<\/li>\n\n\n\n<li>identifier les topics et \u00e9changes.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">TP 5 \u2014 D\u00e9tection de scan r\u00e9seau<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Objectif :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>lancer un scan Nmap ;<\/li>\n\n\n\n<li>d\u00e9tecter les SYN avec tcpdump.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">TP 6 \u2014 Analyse d\u2019un fichier PCAP<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Objectif :<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>ouvrir une capture ;<\/li>\n\n\n\n<li>identifier :\n<ul class=\"wp-block-list\">\n<li>protocoles ;<\/li>\n\n\n\n<li>IP ;<\/li>\n\n\n\n<li>anomalies ;<\/li>\n\n\n\n<li>ports utilis\u00e9s.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>1. Introduction Dans un BTS CIEL ou SIO, tu dois rapidement apprendre \u00e0 diagnostiquer un probl\u00e8me r\u00e9seau, v\u00e9rifier un flux applicatif ou analyser des communications suspectes. tcpdump fait partie des outils incontournables pour ce travail. Cet utilitaire fonctionne directement en ligne de commande. Il capture les paquets r\u00e9seau qui transitent sur une interface et permet [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_import_markdown_pro_load_document_selector":0,"_import_markdown_pro_submit_text_textarea":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[10],"tags":[53,52],"class_list":["post-443","post","type-post","status-publish","format-standard","hentry","category-reseau","tag-tcpdump","tag-wireshark"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Fiche analyse de trafic avec tcpdump - Eryann Breizh SecOps<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/\" \/>\n<meta property=\"og:locale\" content=\"fr_FR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Fiche analyse de trafic avec tcpdump - Eryann Breizh SecOps\" \/>\n<meta property=\"og:description\" content=\"1. Introduction Dans un BTS CIEL ou SIO, tu dois rapidement apprendre \u00e0 diagnostiquer un probl\u00e8me r\u00e9seau, v\u00e9rifier un flux applicatif ou analyser des communications suspectes. tcpdump fait partie des outils incontournables pour ce travail. Cet utilitaire fonctionne directement en ligne de commande. Il capture les paquets r\u00e9seau qui transitent sur une interface et permet [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/\" \/>\n<meta property=\"og:site_name\" content=\"Eryann Breizh SecOps\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-25T15:46:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-25T15:46:54+00:00\" \/>\n<meta name=\"author\" content=\"wpadmin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"wpadmin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Dur\u00e9e de lecture estim\u00e9e\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/reseau\\\/fiche-analyse-de-trafic-avec-tcpdump\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/reseau\\\/fiche-analyse-de-trafic-avec-tcpdump\\\/\"},\"author\":{\"name\":\"wpadmin\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/#\\\/schema\\\/person\\\/d2ee98d2385cd045ed4fe1c07ca320b5\"},\"headline\":\"Fiche analyse de trafic avec tcpdump\",\"datePublished\":\"2026-05-25T15:46:52+00:00\",\"dateModified\":\"2026-05-25T15:46:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/reseau\\\/fiche-analyse-de-trafic-avec-tcpdump\\\/\"},\"wordCount\":1224,\"publisher\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/#organization\"},\"keywords\":[\"tcpdump\",\"wireshark\"],\"articleSection\":[\"R\u00e9seau\"],\"inLanguage\":\"fr-FR\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/reseau\\\/fiche-analyse-de-trafic-avec-tcpdump\\\/\",\"url\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/reseau\\\/fiche-analyse-de-trafic-avec-tcpdump\\\/\",\"name\":\"Fiche analyse de trafic avec tcpdump - Eryann Breizh SecOps\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/#website\"},\"datePublished\":\"2026-05-25T15:46:52+00:00\",\"dateModified\":\"2026-05-25T15:46:54+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/reseau\\\/fiche-analyse-de-trafic-avec-tcpdump\\\/#breadcrumb\"},\"inLanguage\":\"fr-FR\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/eryann.fr\\\/index.php\\\/reseau\\\/fiche-analyse-de-trafic-avec-tcpdump\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/reseau\\\/fiche-analyse-de-trafic-avec-tcpdump\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/eryann.fr\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Fiche analyse de trafic avec tcpdump\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/#website\",\"url\":\"https:\\\/\\\/eryann.fr\\\/\",\"name\":\"Eryann Breizh SecOps\",\"description\":\"Fiches techniques &amp; labs en syst\u00e8mes et r\u00e9seaux poor les \u00e9tudiants en BTS CEIL ET SIO\",\"publisher\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/eryann.fr\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"fr-FR\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/#organization\",\"name\":\"Breizh Sec Ops\",\"url\":\"https:\\\/\\\/eryann.fr\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/eryann.fr\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/cropped-088112b9-fd28-4b18-b02d-4d9dded3e900-e1777846396685.png\",\"contentUrl\":\"https:\\\/\\\/eryann.fr\\\/wp-content\\\/uploads\\\/2026\\\/05\\\/cropped-088112b9-fd28-4b18-b02d-4d9dded3e900-e1777846396685.png\",\"width\":1246,\"height\":229,\"caption\":\"Breizh Sec Ops\"},\"image\":{\"@id\":\"https:\\\/\\\/eryann.fr\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/eryann.fr\\\/#\\\/schema\\\/person\\\/d2ee98d2385cd045ed4fe1c07ca320b5\",\"name\":\"wpadmin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-FR\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d71b4031c3d015de3ca68c137413277e548b331b07db0acf781b9379b798eb3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d71b4031c3d015de3ca68c137413277e548b331b07db0acf781b9379b798eb3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/d71b4031c3d015de3ca68c137413277e548b331b07db0acf781b9379b798eb3e?s=96&d=mm&r=g\",\"caption\":\"wpadmin\"},\"sameAs\":[\"https:\\\/\\\/eryann.fr\"],\"url\":\"https:\\\/\\\/eryann.fr\\\/index.php\\\/author\\\/wpadmin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Fiche analyse de trafic avec tcpdump - Eryann Breizh SecOps","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/","og_locale":"fr_FR","og_type":"article","og_title":"Fiche analyse de trafic avec tcpdump - Eryann Breizh SecOps","og_description":"1. Introduction Dans un BTS CIEL ou SIO, tu dois rapidement apprendre \u00e0 diagnostiquer un probl\u00e8me r\u00e9seau, v\u00e9rifier un flux applicatif ou analyser des communications suspectes. tcpdump fait partie des outils incontournables pour ce travail. Cet utilitaire fonctionne directement en ligne de commande. Il capture les paquets r\u00e9seau qui transitent sur une interface et permet [&hellip;]","og_url":"https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/","og_site_name":"Eryann Breizh SecOps","article_published_time":"2026-05-25T15:46:52+00:00","article_modified_time":"2026-05-25T15:46:54+00:00","author":"wpadmin","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"wpadmin","Dur\u00e9e de lecture estim\u00e9e":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/#article","isPartOf":{"@id":"https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/"},"author":{"name":"wpadmin","@id":"https:\/\/eryann.fr\/#\/schema\/person\/d2ee98d2385cd045ed4fe1c07ca320b5"},"headline":"Fiche analyse de trafic avec tcpdump","datePublished":"2026-05-25T15:46:52+00:00","dateModified":"2026-05-25T15:46:54+00:00","mainEntityOfPage":{"@id":"https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/"},"wordCount":1224,"publisher":{"@id":"https:\/\/eryann.fr\/#organization"},"keywords":["tcpdump","wireshark"],"articleSection":["R\u00e9seau"],"inLanguage":"fr-FR"},{"@type":"WebPage","@id":"https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/","url":"https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/","name":"Fiche analyse de trafic avec tcpdump - Eryann Breizh SecOps","isPartOf":{"@id":"https:\/\/eryann.fr\/#website"},"datePublished":"2026-05-25T15:46:52+00:00","dateModified":"2026-05-25T15:46:54+00:00","breadcrumb":{"@id":"https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/#breadcrumb"},"inLanguage":"fr-FR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/eryann.fr\/index.php\/reseau\/fiche-analyse-de-trafic-avec-tcpdump\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/eryann.fr\/"},{"@type":"ListItem","position":2,"name":"Fiche analyse de trafic avec tcpdump"}]},{"@type":"WebSite","@id":"https:\/\/eryann.fr\/#website","url":"https:\/\/eryann.fr\/","name":"Eryann Breizh SecOps","description":"Fiches techniques &amp; labs en syst\u00e8mes et r\u00e9seaux poor les \u00e9tudiants en BTS CEIL ET SIO","publisher":{"@id":"https:\/\/eryann.fr\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/eryann.fr\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"fr-FR"},{"@type":"Organization","@id":"https:\/\/eryann.fr\/#organization","name":"Breizh Sec Ops","url":"https:\/\/eryann.fr\/","logo":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/eryann.fr\/#\/schema\/logo\/image\/","url":"https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/cropped-088112b9-fd28-4b18-b02d-4d9dded3e900-e1777846396685.png","contentUrl":"https:\/\/eryann.fr\/wp-content\/uploads\/2026\/05\/cropped-088112b9-fd28-4b18-b02d-4d9dded3e900-e1777846396685.png","width":1246,"height":229,"caption":"Breizh Sec Ops"},"image":{"@id":"https:\/\/eryann.fr\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/eryann.fr\/#\/schema\/person\/d2ee98d2385cd045ed4fe1c07ca320b5","name":"wpadmin","image":{"@type":"ImageObject","inLanguage":"fr-FR","@id":"https:\/\/secure.gravatar.com\/avatar\/d71b4031c3d015de3ca68c137413277e548b331b07db0acf781b9379b798eb3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d71b4031c3d015de3ca68c137413277e548b331b07db0acf781b9379b798eb3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d71b4031c3d015de3ca68c137413277e548b331b07db0acf781b9379b798eb3e?s=96&d=mm&r=g","caption":"wpadmin"},"sameAs":["https:\/\/eryann.fr"],"url":"https:\/\/eryann.fr\/index.php\/author\/wpadmin\/"}]}},"_links":{"self":[{"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/posts\/443","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/comments?post=443"}],"version-history":[{"count":1,"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/posts\/443\/revisions"}],"predecessor-version":[{"id":444,"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/posts\/443\/revisions\/444"}],"wp:attachment":[{"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/media?parent=443"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/categories?post=443"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/eryann.fr\/index.php\/wp-json\/wp\/v2\/tags?post=443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}