Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

How to capture traffic with no Wireshark using netsh

From Tech-Wiki


Practical configuration and operational reference for How to capture traffic with no Wireshark using netsh.

Procedure

To start a packet capture (sniffer) in Windows (any version above 7), just use the command below:

netsh trace start capture=yes IPv4.Address=192.168.122.2 tracefile=c:\temp\capture.etl

To stop it, use:

netsh trace stop

the output will be in .ETL format which can be read by Microsoft's Message Analyzer 1.4 or Network Monitor 3.4 (and allows you to save in .pcap format)

You can also convert to .pcap using PowerShell

$s = New-PefTraceSession -Path “C:\temp\OutFile.Cap” -SaveOnStop
$s | Add-PefMessageProvider -Provider “C:\temp\capture.etl”
$s | Start-PefTraceSession

Or use etl2ngcap utility

See also