There is a point to this story, but it has temporarily escaped my mind...
Contact Me MyFaceBook MyLinkedIn MyGitHub MyTwitter

Capturing Network Traffic on Windows 7 and Windows 2008R2

A co-worker of mine recently discovered a very cool feature in Windows 7 and Windows 2008R2. Most people in the computer field already know that if you want to do a network capture, you usually need some kind of tool installed on the OS such as Wireshark or Microsoft Network Monitor. However, he discovered that you can actually capture network traffic directly from the OS. For more information, see

How to start Capturing Traffic

  1. Run an elevated CMD window as administrator
  2. Type in NETSH TRACE START CAPTURE=YES TRACEFILE=c:\temp\mynetworkcapture.etl
  3. At this point, you will be capturing traffic for that box.

How to Stop Capturing Traffic

  1. Run an elevated CMD window as administrator

How to Analyze the Network Capture File

  1. Copy the trace file that was created to a machine with Microsoft Network Monitor 3.4 or Wireshark installed.
  2. If you are opening the trace file in Microsoft Network Monitor 3.4, make sure the parsers are set to WINDOWS profile.

My co-worker thought this was the best thing since sliced bread!

Copyright © 2022 by Julian Easterling. SOME RIGHTS RESERVED.
Privacy Policy              Terms of Use             

Creative Commons License
Except where otherwise noted, content on this site is
licensed under a Creative Common Attribution-Share Alike 4.0 International License.

All of the opinions expressed on this website are those of Julian Easterling and
do not represent the views of any of my current and previous clients or employers in any way.

If you notice an error on the site or content that has not been properly attributed, bring
it to my attention using the contact page and I will endeavor to fix it as soon as I can.

I accept no responsibility or liability for any damages incurred by following any of
my advice or by using any of the information on my site or of those sites that I link to.