{"repo":"mozillazg/ptcpdump","free":true,"listed":false,"github":"https://github.com/mozillazg/ptcpdump","clone":"git clone https://github.com/mozillazg/ptcpdump.git","description":"Process-aware, eBPF-based tcpdump","language":"C","stars":1255,"topics":["ebpf","ebpf-tc","tcpdump","tcpdump-like","ebpf-go","network-capture","packet-capture","forensics","bpf","pcap"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"ptcpdump %20e2e) %20e2e) English 中文 ptcpdump is a tcpdump-compatible packet analyzer powered by eBPF, automatically annotating packets with process/container/pod metadata when detectable. Inspired by jschwinger233/skbdump. Table of Contents ================= Features Installation Requirements Usage Example commands Example output Running with Docker Backend Flags Compare with tcpdump Developing Dependencies Building Related Projects Flownix Features 🔍 Process/container/pod-aware packet capture. 📦 Filter by: --pid (process), --pname (process name), --container-id (container), --pod-name (pod). 🎯 tcpdump-compatible flags ( -i , -w , -c , -s , -n , -C , -W , -A , and more). 📜 Supports pcap-filter(7) syntax like tcpdump. 🌳 tcpdump-like output + process/container/pod context. 📑 Verbose mode shows detailed metadata for processes and containers/pods. 💾 PcapNG with embedded metadata (Wireshark-ready). 🌐 Cross-namespace capture ( --netns ). 🚀 Kernel-space BPF filtering (low overhead, reduces CPU usage). ⚡ Container runtime integration (Docker, containerd). Installation You can download the statically linked executable for x86 64 and arm64 from the releases page. Requirements Linux kernel = 5.2 (compiled with BPF and BTF support). ptcpdump optionally requires debugfs. It has to be mounted in /sys/kernel/debug. In case the folder is empty, it can be mounted with: mount -t debugfs none /sys/kernel/debug The following kernel configuration is required. Building as Modules is also ","default_branch":null,"files":null,"tree":[],"storefront":"/r/mozillazg","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mozillazg/ptcpdump/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}