Basic network capture methods: https://blogs.technet.microsoft.com/askpfeplat/2016/12/27/basic-network-capture-methods/
- Network Monitor 3.4 (Netmon) – https://www.microsoft.com/en-us/download/details.aspx?id=4865 (NOTE: Network Monitor is no longer under active development)
- Wireshark (v 2.2.2 as of 11/16/16) – https://wireshark.org/#download
- Netsh Trace – built-in to operating system
- Microsoft Message Analyzer (MMA) (v 1.4 as of 6/13/16) – https://www.microsoft.com/en-us/download/details.aspx?id=44226
Message analyzer operating guide: http://technet.microsoft.com/en-us/library/jj649776.aspx
How to message analyzer on YouTube: https://www.youtube.com/watch?v=e0v0RsQVdT8
As you might guess from the name, Message Analyzer is much more than a network sniffer or packet tracing tool. Key capabilities include:
- Integrated “live” event and message capture at various system levels and endpoints (client and server remotely !)
- Remote capture (capture multiple point concurrently)
- Parsing and validation of protocol messages and sequences
- Automatic parsing of event messages described by ETW manifests
- Summarized grid display – top level is “operations”, (requests matched with responses)
- User controlled “on the fly” grouping by message attributes
- Ability to browse for logs of different types (.cap, .etl, .txt) and import them together
- Automatic re-assembly and ability to render payloads
- Ability to import text logs, parsing them into key element/value pairs
- Support for “Trace Scenarios” (one or more message providers, filters, and views)
Other articles:
Use message analyzer to convert a .etl to .cap: https://blogs.msdn.microsoft.com/benjaminperkins/2018/03/09/analyze-netsh-traces-with-wireshark-or-network-monitor/
Capture a network trace using netsh:
https://blogs.msdn.microsoft.com/benjaminperkins/2018/03/09/capture-a-netsh-network-trace/
- To learn more about your nmcap options, enter “nmcap /?” or “nmcap /examples”
- Wireshark training can be found at https://www.wireshark.org/#learnWS.
- For more information on Message Analyzer, check out the blog at https://blogs.technet.microsoft.com/messageanalyzer/.
- Message Analyzer training videos can be found at https://www.youtube.com/playlist?list=PLszrKxVJQz5Uwi90w9j4sQorZosTYgDO4.
- Message Analyzer Operating Guide – https://technet.microsoft.com/en-us/library/jj649776.aspx
- Information on the Message Analyzer PowerShell module can be found at https://technet.microsoft.com/en-us/library/dn456518(v=wps.630).aspx.
- Remote captures with MMA – https://blogs.technet.microsoft.com/messageanalyzer/2013/10/17/remote-capture-with-message-analyzer-and-windows-8-1/