ngrep: grep for Network Traffic
Pattern matching against live packet payloads. The syntax, the hex mode, the file interop, and a real capture showing the server name leaking out of an encrypted session.
Pattern matching against live packet payloads. The syntax, the hex mode, the file interop, and a real capture showing the server name leaking out of an encrypted session.
Wireshark’s full dissector library driven from an SSH session: capture filters against display filters, custom field output, ring buffers and the statistics taps that make triage fast.
Local, remote and dynamic forwards, ProxyJump instead of agent forwarding, scp -O against IOS XE, and why telnet is still a fine port tester.
One command joins any two endpoints: TCP, UDP, TLS, UNIX sockets, serial ports or a program. Port forwards, TLS wrappers and protocol bridges from real captures.
Open, refused, timed out and no route to host are four different tickets. Plus banner grabs, file transfer with no server, and why UDP tests lie.
The retry and resume behavior that makes wget worth keeping, spider mode as a health check, rate limiting, and the robots.txt rule that empties your mirror.
Prove a port is open, split DNS from TCP from server think time, test a device API and read a TLS failure, all with real output from a routed lab.
dig tests a nameserver. getent tests name resolution. The full path from nsswitch.conf to the wire, with the resolver deliberately broken and fixed.
One name in, one line out, and the only exit status of the three you can trust. Plus the timing test that complicates the fastest claim.
Declared deprecated for twenty years and still on every machine. What it does well, where it will mislead you, and the debug flag nobody uses.
Read the status line first. Flags, sections, TTLs, delegation traces and DNSSEC, all against a real authoritative server in the lab.
The full command map, wall clock timings on a host holding ten thousand sockets, and the surprise result when you add process lookup.