tcpdump on macOS: Save Traffic to a PCAP File
Use the built-in tcpdump for Mac to create a packet capture, identify the right interface, use macOS process metadata, or upload a capture for analysis. Start with the one-line command, follow the quick guide, see the macOS-specific pktap guide, copy the tcpdump examples, or work through the complete guide.
TL;DR: Capture Mac traffic to a PCAP file
sudo tcpdump -i en0 -s 0 -w capture.pcap
tcpdump ships with macOS, so there is nothing to install. The -s 0
option captures complete packets and -w writes them to capture.pcap.
Quick guide to tcpdump on macOS
- Open Terminal from Applications > Utilities.
- Find the active interface with
route get default | grep interface. Usenetworksetup -listallhardwareportsto map names such asen0anden1to Wi-Fi or Ethernet. - Start a full-packet capture:
sudo tcpdump -vni en0 -s 0 -w capture.pcap -c 100000 - Let tcpdump stop after 100,000 packets, or press Control-C to stop sooner.
macOS-only: pktap and process metadata
Apple's pktap pseudo-interface can attach macOS process metadata to captured
packets. Capture traffic from en0 through pktap and save it as pcapng:
sudo tcpdump -i pktap,en0 -w capture.pcapng
Use pktap,all when you need the macOS equivalent of “any interface,” including
loopback and tunnel interfaces. That broader capture can become noisy, so choose a specific
interface when possible.
When reading that pcapng file, -k NP prints the process name (N) and
process ID (P):
tcpdump -r capture.pcapng -k NP
This lets you see which app made a connection, context that plain tcpdump captures on Linux do
not provide. The -k metadata option is intended for pktap or pcapng data.
Useful tcpdump examples
These copy-and-paste examples cover common tcpdump macOS capture tasks without collecting more packet capture data than you need.
Filter by host and port
sudo tcpdump -i en0 -w web.pcap host 10.0.0.5 and port 443
Stop after 100,000 packets
sudo tcpdump -i en0 -w capture.pcap -c 100000
Keep a 10-file ring buffer
sudo tcpdump -i en0 -w cap.pcap -C 100 -W 10
This keeps 10 files of approximately 100 MB each and replaces the oldest as needed.
Start a new file every hour
sudo tcpdump -i en0 -G 3600 -w 'cap-%Y%m%d-%H%M.pcap'
Disable name and port resolution
sudo tcpdump -i en0 -nn -w capture.pcap
Show MAC addresses
sudo tcpdump -i en0 -e -nn
The -e flag prints the link-layer header, including source and destination MAC addresses.
Reading a pcap file on Mac
Read the beginning of a saved capture without resolving host or service names:
tcpdump -r capture.pcap -nn | head
Terminal output is useful for a quick check, but it does not scale to a large capture. Upload the file and get endpoints, DNS, connections, and suspicious activity in one report.
Complete guide to tcpdump for Mac
macOS has included tcpdump since the early '90s. Tcpdump is a command-line network traffic capture and analysis tool released in 1988. It uses libpcap to capture packets and supports the pcap capture format, making it a practical built-in starting point for a packet capture on Mac.
Open Terminal from Applications > Utilities. Capturing traffic requires access
to macOS BPF devices, so the examples use sudo.
Selecting the right capture interface
Any of these commands can help identify the active interface:
netstat -nr | grep default
route get default | grep interface
networksetup -listallhardwareports
The first two show the interface associated with the default route. The third maps interface
names such as en0 or en1 to Wi-Fi and Ethernet hardware ports. VPNs may
add tunnel interfaces, so choose the interface carrying the traffic you need.
Understanding the capture command
sudo tcpdump -vni en0 -s 0 -w sample.pcap -c 100000
- sudo: grants the privileges needed to capture packets.
- -i en0: captures on the selected interface.
- -n: avoids address-to-name lookups that can slow the capture.
- -s 0: captures complete packets.
- -w sample.pcap: writes packets to a pcap file.
- -c 100000: stops after 100,000 packets.
- -v: increases the progress information tcpdump prints.
You can stop the capture at any time with Control-C. Check the file size from
another Terminal window with ls -lh sample.pcap.
Troubleshooting
tcpdump: en0: You don't have permission to capture on that device (/dev/bpf…)
Run tcpdump with sudo. If Wireshark's ChmodBPF component is installed, it can grant
members of its access group permission to use the BPF capture devices without running the whole
application as root.
Which interface should I capture on?
Run route get default | grep interface to find the default-route interface, then use
networksetup -listallhardwareports to tell whether that device is Wi-Fi or Ethernet.
Can I see which app made a connection?
Yes. Capture through Apple's pktap pseudo-interface into pcapng, then read it with
-k NP to print the process name and PID, as shown in the pktap section above.
For other messages, see Common tcpdump Errors and Solutions.
Now that you have your PCAP file...
Use it to discover malicious activity, security vulnerabilities, and other interesting network events.
