tcpdump

Output speichern in Wireshark-kompatiblem Format: -w filename.cap