Network Monitor capture files that cannot be translated to pcap or pcapng files

I need to capture some traffic using Microsoft Network Monitor because I need to select only some process ids. This application, unfortunately, only produces .cap files of type "Microsoft NetMon 2.x" but those files cannot be translated in "Wireshark/tcpdump/... - pcap" type, the only one read by the network analyzer Bro. Wireshark, in fact, can read those .cap file but is not able to save them with its own types. How can I solve?

Is this a Wi-Fi capture? If so, then, as I said in the answer to the question indicated below:

...there's no pseudo link-layer header type for the NetMon flavor of 802.11 radio data pseudo-header, and Wireshark currently doesn't try to map 802.11 radio data pseudo-headers to a "common" format so that it could use, for example, radiotap headers.

which means that those files can't be translated to pcap or pcapng - and, even if a new pcap/pcapng pseudo-link-layer-header type were added for NetMon's 802.11 radio data, Bro might have to be changed to support that type (to skip it, if nothing else).

Guy Harris

answered 2018-05-04 12:47:45 +0000

NJL

Have you tried the CLI tool editcap.exe? That should be able to solve your task.

It says: --File myfile.cap is a Microsoft NetMon 2.x capture file. --editcap: The capture file being read can't be written as a "pcapng" file.

simone

Found this thread which is very similar and at the very bottom is a comment from someone with a home-grown utility. You could try to reach out and see if it's still available although the thread isn't exactly recent...

NJL

