{"repo":"microsoft/etl2pcapng","free":true,"listed":false,"github":"https://github.com/microsoft/etl2pcapng","clone":"git clone https://github.com/microsoft/etl2pcapng.git","description":"Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.","language":"C","stars":736,"topics":["etl","wireshark","packet-capture"],"license":"MIT","category":"data-pipelines","readme_excerpt":"About This tool enables you to view ndiscap and pktmon packet captures with Wireshark. Due to performance problems with the other popular packet capture method (WinPcap, which was included with older versions of Wireshark), these inbox tools should be preferred. Windows has several inbox components capable of packet capture: - \"pktmon\" is implemented as an integral part of the Windows operating system. It's capable of capturing packets in many components of the operating system, giving full visibility into the life of the packet as it traverses the system. A capture can be collected with: - \"ndiscap\" which is implemented as an ETW trace provider. A capture can be collected with: The files generated by these tools are etl files, which can be opened by ETW-centric tools like Microsoft Message Analyzer, but cannot be opened by Wireshark, which is the preferred tool for many engineers. Etl2pcapng.exe can convert the etl file to a pcapng file for opening with Wireshark, or for analysis with languages that have pcapng libraries available such as Python and Rust. Note: pktmon has a built-in etl2pcap conversion utility (\"pktmon etl2pcap \\ \") which is also capable of producing basic pcapng files. etl2pcapng provides a similar conversion capability to the built-in utility with the following additions: - Preserving all used components as pcapng interfaces. - Providing additional information about each interface in the interface description block such as the Name, Description, IP address","default_branch":null,"files":null,"tree":[],"storefront":"/r/microsoft","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/microsoft/etl2pcapng/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}