yeetyeet
docs
articles
blogtopical takes
pricingaboutcareers
Login / RegisterBook a demo

Topical Takes

Short, opinionated posts on eBPF, Linux internals, and the tools we all run in production.

AlleBPF10linux9observability6yeet6networking3tcpdump3AI agents2HTTP2kubernetes2802.111ai-sre1audit1Cilium1claude-code1integration-testing1opentelemetry1packet-capture1Redis1RESP1rf1root-cause-analysis1security1slowlog1tunnels1uprobes1websocket1wifi1wireguard1wireless1wss1+30 more
AlleBPF10linux9observability6yeet6networking3tcpdump3AI agents2HTTP2kubernetes2802.111ai-sre1audit1Cilium1claude-code1integration-testing1opentelemetry1packet-capture1Redis1RESP1rf1root-cause-analysis1security1slowlog1tunnels1uprobes1websocket1wifi1wireguard1wireless1wss1
August 24, 2026

How to Capture Packets on wg0 and Other Tunnel Interfaces on Linux: The Ethernet Header Is Not Missing, It Was Never There

Capturing on wg0, gre1 or tun0 hands you a bare IP packet, because a raw-IP tunnel device has no MAC header to give you; pktscope is a terminal packet analyzer whose TCX eBPF tap starts the snap at the MAC header on Ethernet-framed devices and at the network header on tunnels, so the decode and the hex offsets match the device you picked.

tunnelswireguardpacket-capturetcpdumpeBPFlinuxnetworkingyeet
Read more →
FECM

yeet

Made in Chicago with ❤️

JavaScript at the kernel boundary. Build the tool you need, run it in seconds.

★772

© 2026 Virt Inc.

Product

DocsBlogTopical Takes

Company

Contact usTermsPrivacy