Dumpcap用于提升网络安全的可落地方案
一 核心思路
二 权限最小化与系统加固
sudo usermod -aG wireshark <username>sudo setcap 'cap_net_raw,cap_net_admin+eip' /usr/bin/dumpcap(路径以实际安装为准,常见为**/usr/bin/dumpcap或/usr/sbin/dumpcap**)PermitRootLogin no),减少横向移动风险。三 捕获策略与过滤配置
sudo dumpcap -i eth0 -f "port 80" -w http.pcapsudo dumpcap -i eth0 -f "tcp port 80 and host example.com" -w example_http.pcapsudo dumpcap -i eth0 -c 100 -w capture.pcapsudo dumpcap -i eth0 -G 60 -W bysec -w capture_%Y-%m-%d_%H-%M-%S.pcap(每60秒一个文件)四 日志监控与合规
五 快速命令清单
sudo apt update && sudo apt install wireshark -y,dumpcap --versionsudo usermod -aG wireshark <username>,sudo setcap 'cap_net_raw,cap_net_admin+eip' /usr/bin/dumpcapdumpcap -i eth0 -w output.pcapsudo dumpcap -i eth0 -f "tcp port 80 and host example.com" -w example_http.pcapsudo dumpcap -i eth0 -G 60 -W bysec -w cap_%Y-%m-%d_%H-%M-%S.pcap,sudo dumpcap -i eth0 -c 100 -w capture.pcaptshark -r capture.pcap -Y "http" -T fields -e frame.number -e ip.src -e ip.dst -e http.host -e http.request.method -e http.request.uri