Many developers, security enthusiasts, and power users need to see exactly what data their phone is sending and receiving. Whether you are debugging an app, checking for unwanted ads, or verifying that a VPN is really encrypting traffic, a raw packet capture (PCAP) gives you the most accurate view.
Android does not ship with a built‑in packet sniffer, and most commercial sniffers require root. Fortunately, the open‑source tool tcpdump can run from the device’s user space when you push it with ADB. This tutorial shows you how to do it safely, without rooting, on any Android 5.0+ device.
adb version.tcpdump is compiled for different CPU architectures. Most modern phones use arm64-v8a or armeabi‑v7a. Choose the binary that matches your device.
tcpdump-arm64 for 64‑bit devices or tcpdump-arm for 32‑bit devices.tcpdump (no extension) for simplicity.If you are unsure about the architecture, you can query the device via ADB:
adb shell getprop ro.product.cpu.abi
Typical outputs:
arm64-v8a → use the arm64 binary.armeabi-v7a → use the arm binary.adb devices
You should see your device listed as device./data/local/tmp, a writeable location that does not require root:
adb push tcpdump /data/local/tmp/adb shell chmod 755 /data/local/tmp/tcpdumpadb shell /data/local/tmp/tcpdump -h
You should see the usage text, confirming the binary runs.
If you receive Permission denied, double‑check that you pushed the file to /data/local/tmp and not to a system directory.
Android devices usually have at least two interfaces: wlan0 for Wi‑Fi and rmnet0 (or similar) for cellular. To list them:
adb shell "cat /proc/net/dev"
Look for the interface names in the left column. Choose the one that matches the connection you are testing.
/sdcard/Download because it is easy to pull later.
CAP_FILE="/sdcard/Download/android_capture.pcap"
-i flag selects the interface, -w writes raw packets, and -s 0 captures the full packet length.
adb shell "su -c '/data/local/tmp/tcpdump -i wlan0 -s 0 -w $CAP_FILE'"
Note: On non‑rooted devices the su -c wrapper is not needed; the command can be executed directly. The example includes it for devices that have a temporary root shell via adb root, but most users will omit it:
adb shell "/data/local/tmp/tcpdump -i wlan0 -s 0 -w $CAP_FILE"
Typical output looks like:
tcpdump: listening on wlan0, link-type EN10MB (Ethernet), capture size 65535 bytes
When you stop the capture, you will see a line such as 123 packets captured.
Now that the capture is saved on the device, copy it to your analysis workstation:
adb pull /sdcard/Download/android_capture.pcap ./
The file is now ready for inspection with Wireshark, tshark, or any other PCAP viewer.
Open the file in Wireshark and apply a simple filter to verify you captured the intended traffic, for example:
httpdnsip.addr == 93.184.216.34If you see packets, the capture succeeded. If the file is empty, revisit the interface name and ensure the device was actively using that network during the capture window.
On some OEM skins, the /data/local/tmp directory is mounted with the nosuid flag, preventing execution of binaries that need raw sockets. In that case, try pushing the binary to /data/local/tmp and executing it with the run-as trick for a specific app’s UID:
adb shell "run-as com.android.shell /data/local/tmp/tcpdump -i wlan0 -s 0 -w /sdcard/Download/capture.pcap"
If this still fails, the device may block raw socket access for non‑system users. The only reliable workaround is to use a rooted device or a custom recovery that allows packet capture.
/sdcard/Download folder must be writable. You can test with a simple adb shell touch /sdcard/Download/test.txt./sdcard from ADB shell. Use /data/local/tmp instead, then pull the file from there.Ensure USB debugging is still enabled and the USB cable is data‑capable. On Windows, reinstall the Google USB driver. On macOS/Linux, you may need to add your user to the plugdev group.
Use the -c flag to limit the number of packets, or the -W flag to rotate files after a size threshold. Example to stop after 10,000 packets:
adb shell "/data/local/tmp/tcpdump -i wlan0 -s 0 -c 10000 -w /sdcard/Download/capture.pcap"
tcp port 443 to record only HTTPS traffic.
adb shell "/data/local/tmp/tcpdump -i wlan0 -s 0 -w /sdcard/Download/https.pcap tcp port 443"
adb shell "nohup /data/local/tmp/tcpdump -i wlan0 -s 0 -w /sdcard/Download/bg.pcap &"
Remember to kill it later with adb shell pkill -f tcpdump.
Capturing network traffic can expose passwords, tokens, and personal data. Treat the resulting PCAP file as sensitive:
Because the method uses a user‑space binary, it does not modify system partitions, so there is no risk of bricking the device. However, running any executable from an unknown source carries a small security risk. Only download tcpdump from reputable mirrors.
By following these steps you have installed tcpdump on a non‑rooted Android phone, captured live network traffic, and exported the data for deep analysis. The workflow is repeatable, works across most manufacturers, and does not require flashing custom recoveries or unlocking the bootloader.
Use the captured data to verify VPN tunnels, debug app networking, audit data‑leakage, or simply satisfy curiosity about what your phone talks to on the internet. With the troubleshooting notes above, you should be able to adapt the process to edge‑case devices and avoid the most common pitfalls.









