如何用tcpdump在多台Memu模拟器中分别拦截并保存网络流量?
Got it, let's break down how to solve this—whether you want to capture traffic per Memu emulator instance or per individual app inside each emulator. I'll cover both your current Windows setup and note if switching OS could simplify things.
1. Capture Traffic Per Memu Emulator Instance (Host-Side Tcpdump)
Each Memu emulator runs on its own dedicated virtual network adapter, so we can target each adapter to isolate traffic cleanly.
Step 1: Identify Memu's Virtual Adapters
- Open an Administrator Command Prompt and run:
This lists all network adapters on your system. Look for entries namedtcpdump -DVirtualBox Host-Only Ethernet Adapter #X(Memu uses VirtualBox under the hood). Each#Xmaps to one emulator instance (e.g., emu1 = #1, emu2 = #2). - Alternatively, check Windows' Network Connections panel: Go to Control Panel > Network and Sharing Center > Change adapter settings. Memu's adapters will be clearly labeled here too.
Step 2: Prepare Target Folders
Create your output folders first to avoid errors:
mkdir C:\MemuTraffic\folder1 mkdir C:\MemuTraffic\folder2 mkdir C:\MemuTraffic\folder3
Step 3: Run Tcpdump for Each Emulator
Launch a separate Command Prompt window (as Admin) for each emulator, then run:
# For emu1 (using adapter #1) tcpdump -i "VirtualBox Host-Only Ethernet Adapter #1" -w C:\MemuTraffic\folder1\emu1_full_traffic.pcap # For emu2 (using adapter #2) tcpdump -i "VirtualBox Host-Only Ethernet Adapter #2" -w C:\MemuTraffic\folder2\emu2_full_traffic.pcap
- The
-iflag specifies which adapter to monitor,-wwrites the capture to a file. - Leave each command running while the emulator is active; press
Ctrl+Cto stop capturing when done.
2. Capture Traffic Per App Instance (Emulator-Side Tcpdump)
If you need to isolate traffic from individual app instances (app1, app2) inside a single emulator, you'll need to run tcpdump directly inside the emulator and filter by the app's activity.
Step 1: Enable ADB Access for Memu
- Open your Memu emulator, go to Settings > Developer Options and enable USB debugging.
- From your Windows command prompt, connect to the emulator via ADB:
Memu uses sequential ports starting at 21503 for the first emulator instance.adb connect 127.0.0.1:21503 # Default port for emu1; emu2 uses 21513, emu3 21523, etc.
Step 2: Install Tcpdump on the Emulator
- Grab an ARM-compatible tcpdump binary (you can find pre-built versions online, or use Memu's built-in package manager if available). Push it to the emulator:
adb push C:\path\to\your\tcpdump /data/local/tmp/ adb shell chmod 755 /data/local/tmp/tcpdump
Step 3: Capture App-Specific Traffic
- First, find the app's UID (user ID) to filter traffic:
Look for the UID column in the output.adb shell ps | grep com.your.app.package - Run tcpdump inside the emulator, filtering by the app's UID:
adb shell /data/local/tmp/tcpdump -i any -w /sdcard/app1_traffic.pcap owner <APP_UID> - Pull the capture file to your Windows folder when done:
adb pull /sdcard/app1_traffic.pcap C:\MemuTraffic\folder1\app1_traffic.pcap
Alternative: Switching to Linux for Easier Automation
If you're open to changing OS, Linux simplifies this workflow a lot:
- Memu runs smoothly via Wine, and you can use tools like
bashscripts to automate starting captures for all emulators/apps at once. - Tcpdump integrates seamlessly with virtual network interfaces, and tools like
tshark(Wireshark's CLI) make filtering app-specific traffic even more straightforward.
Quick Notes
- Always run tcpdump with administrative privileges (Windows) or root (inside emulators) to capture all traffic.
- To analyze the
.pcapfiles, use Wireshark—it's free, cross-platform, and perfect for digging into captured traffic. - If you have dozens of emulators/apps, writing a simple batch script (Windows) or bash script (Linux) will save you tons of manual work.
内容的提问来源于stack exchange,提问作者CuriousPanda

