@TOC
查询tcp
tcp
data:image/s3,"s3://crabby-images/1880f/1880f822ead25cc529eca2087e18344a364c1082" alt=""
查询tcp握手请求的代码
tcp.flags.ack == 0
data:image/s3,"s3://crabby-images/51382/513823bdc1f70dc09e54e3554cce5077a833399f" alt=""
确定tcp握手成功的代码
tcp.flags.ack == 1
data:image/s3,"s3://crabby-images/da5e8/da5e83ad7f0ffa98bb74f337ae13c8c2892a8fb6" alt=""
确定tcp连接请求的代码
tcp.flags.ack == 0 and tcp.flags.syn == 1
data:image/s3,"s3://crabby-images/0bef0/0bef05c9effbb77a1d1bb5328070165744f0c141" alt=""
3次握手后确定发送成功的查询
tcp.flags.fin == 1
data:image/s3,"s3://crabby-images/4b0d5/4b0d5b6f768218f58450f25caa571270c37bda2a" alt=""
查询某IP对外发送的数据
ip.src_host == 192.168.73.134
data:image/s3,"s3://crabby-images/0d6ae/0d6ae86bf5f1f59ff3fdb9f0a23f1fcb9ac8ae81" alt=""
查询某IP向某IP发送的数据
ip.src_host == 192.168.73.134 and ip.dst_host == 36.103.205.147
(ip.src_host == 192.168.73.134 and ip.dst_host == 36.103.205.147) or ( ip.src_host == 36.103.205.147 and ip.dst_host == 192.168.73.134)
data:image/s3,"s3://crabby-images/11269/112690dd7f117d0e7aa364b7088b3762f6c7e3bd" alt=""