Remote tcpdump sniffer with source filtering
- Add any filter you want to the tcpdump command inside
tcpdump.powto filter any traffic you don't want to be sniffed! - For the sake of simplicity run
sudo kapow server tcpdump.pow. In a production environment tcpdump should be run with the appropiate permissions but kapow can (and should) run as an unprivilieged user. - In your local machine run:
Again, for the sake of simplicity Wireshark is running as root. If you don't want to run it this way follow this guide: https://gist.github.com/MinaMikhailcom/0825906230cbbe478faf4d08abe9d11a
curl http://localhost:8080/sniff/<network-interface> | sudo wireshark -k -i - - Profit!