How can I convert Microsoft NetMon .cap files to a different format?
I have been given some monstrous Microsoft NetMon .cap files to analyze. I want to pull out particular flows (tcp.stream) to examine them in detail and give to someone else to look at. But upon loading the file I see "Save" and "Save As" greyed out. When trying to use "editcap -F" to convert to .pcap or .pcapng, respectively, give "editcap: The capture file being read can't be written as a "pcap" file." and "editcap: Frame 1 of file <the file="" name=""> has a network type thyat can't be3 saved in a "pcapng" file."
I'm running 4.2.13 (v4.2.13-0gef715502a09c). I loaded up 4.4 and that didn't help. The decode of the first packet says "Encapsulation type: Network Monitor Filter (189)", "Version: 1", App Major Version: 196612" and "App Minor Version: 154009600"