This is our old Q&A Site. Please post any new questions and answers at

I would like to know if it possible to zero it on a packet capture by finding the the first syn ack and then find all sites associated with this.

asked 16 Oct '10, 12:35

eparl's gravatar image

accept rate: 0%

Can you give a little more explanation? I'm assuming you have a large packet capture and you're looking to find a session initialization (the SYN ACK). Once you find the pertinent session(s) you want to find all "sites"? This is the confusing part.

(19 Oct '10, 07:38) GeonJay

When I want to find the first TCP SYN in a packet capture, I'll open the Find dialog ("CTRL+F" or Edit | Find Packet) and apply the following display filter:

tcp.flags eq 0x02

This will bring you to the first TCP SYN packet in the packet capture. If you want a list of all the sites associated with this host (I'm not sure if you mean source or destination host), I right-click on the IP address in question and select Apply as Filter | Selected.


permanent link

answered 19 Oct '10, 05:59

joswr1ght's gravatar image

accept rate: 0%

Your answer
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here



Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text]( "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:


question asked: 16 Oct '10, 12:35

question was seen: 3,355 times

last updated: 19 Oct '10, 07:38

p​o​w​e​r​e​d by O​S​Q​A