groupadd tcpdump
addgroup <username> tcpdump
chown root.tcpdump /usr/sbin/tcpdump
chmod 0750 tcpdump
setcap "CAP_NET_RAW+eip" /usr/sbin/tcpdump
ssh user@host 'sudo tcpdump -i eth0 host <ip> and no port 22' | wireshark -
tcpdump2dot/dist/latest.tar.gz