Software Alternatives & Reviews

lsof VS tcpdump

Compare lsof VS tcpdump and see what are their differences

lsof logo lsof

Lsof lists open files for running UNIX processes. It is a

tcpdump logo tcpdump

tcpdump is a common packet analyzer that runs under the command line.
  • lsof Landing page
    Landing page //
    2019-09-16
  • tcpdump Landing page
    Landing page //
    2023-04-27

lsof videos

8 Basic lsof Commands Every Sysadmin Needs to Know

More videos:

  • Review - HakTip - Network monitoring in Linux with lsof

tcpdump videos

Tcpdump - Protocol Review 5 (TCP)

More videos:

  • Review - Tcpdump - Protocol Review 3 (UDP)
  • Review - Tcpdump - Protocol Review 4 (DNS) - Draft

Category Popularity

0-100% (relative to lsof and tcpdump)
Monitoring Tools
10 10%
90% 90
IDE
100 100%
0% 0
Log Management
6 6%
94% 94
Command Line Tools
100 100%
0% 0

User comments

Share your experience with using lsof and tcpdump. For example, how are they different and which one is better?
Log in or Post with

Reviews

These are some of the external sources and on-site user reviews we've used to compare lsof and tcpdump

lsof Reviews

We have no reviews of lsof yet.
Be the first one to post

tcpdump Reviews

6 Best Wireshark Alternatives for Windows and macOS
The quickness that you can have with tcpdump over Wireshark is awesome. It is one of those tools that many network administrators prefer whenever they need to take a look at the actual network packets that are being transmitted. The Tcpdump is not as feature rich as Wireshark but the output of its packet dump can be used as input by other programs. Moreover, It can be used...
Source: techwiser.com

What are some alternatives?

When comparing lsof and tcpdump, you can also consider the following products

strace - Trace system calls and signals. A diagnostic, debugging and instructional userspace utility.

Wireshark - Wireshark is a network protocol analyzer for Unix and Windows. It lets you capture and interactively browse the traffic running on a computer network.

htop - htop - an interactive process viewer for Unix. This is htop, an interactive process viewer for Unix systems. It is a text-mode application (for console or X terminals) and requires ncurses. Latest release: htop 2.

netcat - Netcat is a featured networking utility which reads and writes data across network connections...

ftrace - A function tracer for the Linux kernel.

Ettercap - Ettercap is a suite for man in the middle attacks on LAN.