john pfeiffer
  • Home
  • Categories
  • Tags
  • Archives

wireshark winpcap npf windows

download winpcap drivers download windump (portable?)

right click on cmd.exe -> open as administrator net start npf

Choose an interface and start a capture, do a transaction then stop a capture

Filter: ip.src == 1.2.3.4 OR ip.dst == 1.2.3.4

Analyze -> Follow TCP Stream


  • « threads logger log4j commandline parameters array to arraylist
  • outlook pst linux mbox readpst »

Published

Nov 2, 2012

Category

research

~42 words

Tags

  • npf 1
  • research 199
  • windows 72
  • winpcap 1
  • wireshark 1