tcpflow
tcpflow copied to clipboard
Example usage is out of date
The example tcpflow
usage in manual is out of date (for >= 1.3). It uses option -e
for http processing and this option AFAIK is currently used for scanners.
The example:
To record all packets arriving at or departing from sundown and extract all of the HTTP attachments:
tcpflow -e scan_http -o outdir host sundown