tcpdump is an authoritative command line packet analyzer which makes use of libpcap (a portable C/C++ library) for network traffic capture. While there are other tools for network forensics such as WireShark, tcpdump has it’s strength with respect to TCP packets. The program allows in depth analysis of tcp packets from the interface it runs on.

