I had a doubt about a tcpdump capture.
I have to capture all post request on the sniffed host, and I know how to do this; I found here and on other site how to capture, for example, all post request on a web server with filter like:
tcpdump -i enp0s8 -s 0 -A 'tcp[((tcp[12:1] & 0xf0) >> 2):4] = 0x504F5354'
But I wonder: it is possible to capture only the request for specific path exposed on server?
For example, suppose that I have the www.site.com and on this site I have the following path:
www.site.com/test/folder
www.site.com/update/download
is it possible to create a tcpdump filter to capture only post request for /test/folder and /update/download path?