Browse documentation

Using Redhound

Ruby 3.3 or later is required. File analysis needs no capture privileges. Live capture uses Linux AF_PACKET or macOS BPF devices and normally requires root or an appropriate device/capability grant. Runtime dependencies are Ruby’s standard libraries; neither libpcap nor a native extension is required.

redhound -D
sudo redhound -i any 'tcp port 443'
sudo redhound -i en0 -c 100 -w trace.pcapng
sudo chown "$(id -un)" trace.pcapng
redhound -r trace.pcapng -T tree
redhound -r trace.pcap -T ndjson 'udp port 53'
redhound -r trace.pcap -T fields -e ip.src -e tcp.dstport
redhound -r trace.pcap --stats conv,tcp --stats io,1
redhound -r trace.pcap --follow tcp,ascii,0

Options must precede the filter expression. Quote filters containing shell operators. Addresses are numeric by default; -N enables name resolution. --help lists every option. --list-protocols lists registered protocols and their declared fields. Dynamic fields also appear in detailed and JSON output.

Options for tcpdump users

tcpdump Redhound
-i, -D, -c, -s, -p, -B, -Q Same purpose; -i any is Linux only
-r, -w, -U Read/write pcap or pcapng; - selects stdin/stdout
-C, -G, -W Size/time rotation and file count
-e, -q, -v, -vv, -vvv Link header, short output, increasing detail/checksums
-t through -ttttt No time, epoch, delta, date/time, elapsed time
-x, -xx, -X, -XX Hex/ASCII, optionally including the link header
-F, -d, -dd, -ddd Filter file and cBPF listing
-Z USER Drop user/group privileges after opening capture and output

See supported capture filters. Capture filters select packets; Wireshark display filters are not supported. --decode-as udp.port==8443,dns overrides port dispatch. -I plugin.rb loads a Ruby dissector before capture.

Saving and rotation

-w alone saves raw packets without dissection. Add -T summary or -V to also display them. Binary output to stdout cannot be combined with text output. --format pcapng overrides the extension. pcapng preserves interface identities, nanosecond timestamps, packet directions and available drop statistics.

-C uses decimal megabytes; -G uses seconds. Rotated files receive a five-digit sequence before the extension. With -C -W, names form an overwrite ring. With -G -W alone, capture stops after the requested number of files. -G expands strftime directives in the base name. Rotation happens when the next packet arrives. --post-rotate-command 'gzip -f' invokes an argument vector, appending the closed filename; it does not invoke a shell. Input files and their aliases are protected from output truncation, including rotated destinations.

Analysis and termination

Displayed TCP packets receive stream IDs and analysis flags. IP fragments and TCP application messages are reassembled within bounded state. Conflicting IPv6 overlaps discard the datagram; IPv4/TCP retain first-seen bytes and report conflicts. Incomplete, expired or evicted state is diagnosed, not retained indefinitely. --follow tcp,raw,N emits the selected stream bytes without headers; ASCII and hex modes label the endpoints and directions.

Statistics accept io,SECONDS, conv,eth|ip|ipv6|tcp|udp, endpoints,eth|ip|ipv6|tcp|udp, or phs; options can be repeated. Packet counts and byte totals use captured packets and original frame lengths. SIGUSR1 (and SIGINFO on macOS) prints a statistics snapshot; SIGINT/SIGTERM close output and capture sources cleanly. Capture statistics go to stderr. Exit status is 0 on success, 1 on capture/file failures and 2 on invalid arguments.

Platforms and limits

Linux auto uses TPACKET_V3 on x86_64 and aarch64 and falls back to the socket backend when mapping is unavailable. Other Linux architectures default to sockets; ring can be selected explicitly. macOS uses BPF, with native timestamp precision reported by the device. Linux socket capture cannot recover NIC-stripped VLAN tags; choose the ring backend for that metadata. Ruby 4.0’s IO::Buffer.map rejects packet sockets, so auto uses socket capture and explicit ring reports the mapping limitation. Use Ruby 3.3/3.4 for ring capture. If using sockets, disable receive VLAN offload on the receiving interface when VLAN tags are required (ethtool -K IF rxvlan off).

Windows, Wi-Fi monitor mode, packet transmission, TLS decryption, complete HTTP/2/QUIC dissection, display-filter syntax and a TUI are outside v2’s scope. See release validation status before promoting a prerelease.