Welcome to ptcpdump!

Get Started View on GitHub

Process-aware, eBPF-based tcpdump

Process/Container Aware

Capture packets with full process, container, and Kubernetes pod context.

tcpdump Compatible

Use the same flags and filter syntax you already know, like -i, -w, -A, and pcap-filter(7).

PcapNG with Metadata

Save captures in PcapNG format with embedded metadata, ready for deep analysis in Wireshark.