Software-based tools and commands
In this section, we will discuss some of the most common software tools and commands that technicians use to gather data within their networks.
Packet sniffer
A packet sniffer is a program used to capture packets traversing a network. TCPdump is a command-line packet sniffer, while other packet sniffers may have a graphical user interface, such as Wireshark. A packet sniffer is commonly combined with a protocol analyzer so that network professionals can capture and analyze traffic using a single piece of software. Under normal network configurations, packet sniffers can only capture unicast traffic directed at the host machine, multicast, and broadcast traffic on the network.
The following screenshot shows TCPdump capturing live packets on a network:
Figure 17.9 – A TCPdump packet capture
Therefore, network professionals usually configure monitoring ports on switches or utilize hubs to repeat traffic from other...