tcpdump on macOS: Save Traffic to a PCAP File

Use the built-in tcpdump for Mac to create a packet capture, identify the right interface, use macOS process metadata, or upload a capture for analysis. Start with the one-line command, follow the quick guide, see the macOS-specific pktap guide, copy the tcpdump examples, or work through the complete guide.

See also: Creating PCAP Files on Windows or Linux.

TL;DR: Capture Mac traffic to a PCAP file

sudo tcpdump -i en0 -s 0 -w capture.pcap

tcpdump ships with macOS, so there is nothing to install. The -s 0 option captures complete packets and -w writes them to capture.pcap.

Quick guide to tcpdump on macOS

  1. Open Terminal from Applications > Utilities.
  2. Find the active interface with route get default | grep interface. Use networksetup -listallhardwareports to map names such as en0 and en1 to Wi-Fi or Ethernet.
  3. Start a full-packet capture:
    sudo tcpdump -vni en0 -s 0 -w capture.pcap -c 100000
  4. Let tcpdump stop after 100,000 packets, or press Control-C to stop sooner.

macOS-only: pktap and process metadata

Apple's pktap pseudo-interface can attach macOS process metadata to captured packets. Capture traffic from en0 through pktap and save it as pcapng:

sudo tcpdump -i pktap,en0 -w capture.pcapng

Use pktap,all when you need the macOS equivalent of “any interface,” including loopback and tunnel interfaces. That broader capture can become noisy, so choose a specific interface when possible.

When reading that pcapng file, -k NP prints the process name (N) and process ID (P):

tcpdump -r capture.pcapng -k NP

This lets you see which app made a connection, context that plain tcpdump captures on Linux do not provide. The -k metadata option is intended for pktap or pcapng data.

Useful tcpdump examples

These copy-and-paste examples cover common tcpdump macOS capture tasks without collecting more packet capture data than you need.

Filter by host and port
sudo tcpdump -i en0 -w web.pcap host 10.0.0.5 and port 443
Stop after 100,000 packets
sudo tcpdump -i en0 -w capture.pcap -c 100000
Keep a 10-file ring buffer
sudo tcpdump -i en0 -w cap.pcap -C 100 -W 10

This keeps 10 files of approximately 100 MB each and replaces the oldest as needed.

Start a new file every hour
sudo tcpdump -i en0 -G 3600 -w 'cap-%Y%m%d-%H%M.pcap'
Disable name and port resolution
sudo tcpdump -i en0 -nn -w capture.pcap
Show MAC addresses
sudo tcpdump -i en0 -e -nn

The -e flag prints the link-layer header, including source and destination MAC addresses.

Reading a pcap file on Mac

Read the beginning of a saved capture without resolving host or service names:

tcpdump -r capture.pcap -nn | head

Terminal output is useful for a quick check, but it does not scale to a large capture. Upload the file and get endpoints, DNS, connections, and suspicious activity in one report.

Complete guide to tcpdump for Mac

macOS has included tcpdump since the early '90s. Tcpdump is a command-line network traffic capture and analysis tool released in 1988. It uses libpcap to capture packets and supports the pcap capture format, making it a practical built-in starting point for a packet capture on Mac.

Open Terminal from Applications > Utilities. Capturing traffic requires access to macOS BPF devices, so the examples use sudo.

Selecting the right capture interface

Any of these commands can help identify the active interface:

netstat -nr | grep default
route get default | grep interface
networksetup -listallhardwareports

The first two show the interface associated with the default route. The third maps interface names such as en0 or en1 to Wi-Fi and Ethernet hardware ports. VPNs may add tunnel interfaces, so choose the interface carrying the traffic you need.

Find the tcpdump interface on macOS
Understanding the capture command
sudo tcpdump -vni en0 -s 0 -w sample.pcap -c 100000
  • sudo: grants the privileges needed to capture packets.
  • -i en0: captures on the selected interface.
  • -n: avoids address-to-name lookups that can slow the capture.
  • -s 0: captures complete packets.
  • -w sample.pcap: writes packets to a pcap file.
  • -c 100000: stops after 100,000 packets.
  • -v: increases the progress information tcpdump prints.

You can stop the capture at any time with Control-C. Check the file size from another Terminal window with ls -lh sample.pcap.

tcpdump on Mac saving a PCAP file

Troubleshooting

tcpdump: en0: You don't have permission to capture on that device (/dev/bpf…)

Run tcpdump with sudo. If Wireshark's ChmodBPF component is installed, it can grant members of its access group permission to use the BPF capture devices without running the whole application as root.

Which interface should I capture on?

Run route get default | grep interface to find the default-route interface, then use networksetup -listallhardwareports to tell whether that device is Wi-Fi or Ethernet.

Can I see which app made a connection?

Yes. Capture through Apple's pktap pseudo-interface into pcapng, then read it with -k NP to print the process name and PID, as shown in the pktap section above.

For other messages, see Common tcpdump Errors and Solutions.

Now that you have your PCAP file...

Use it to discover malicious activity, security vulnerabilities, and other interesting network events.


ONLINE PCAP ANALYZER

Analyze a macOS tcpdump capture