Upgraded to windows 10, seeing far more accurate & detailed info under "Transport Address"?

asked 2019-02-01 00:39:25 +0000

dids201 gravatar image

Whats going on here. It seems Wireshark is 10x more accurate in resolving transport addresses in windows 10, has there been some major changes to the TCPIP stack that allow for wireshark to more accurately glean information???

edit retag flag offensive close merge delete

Comments

Please specify what 'accurate' means in your observation.

Jaap gravatar imageJaap ( 2019-02-01 07:14:41 +0000 )edit

Im seeing dozens of new transport address names which I don't remember seeing before.

dids201 gravatar imagedids201 ( 2019-02-03 11:08:28 +0000 )edit

What version of Wireshark are you using?

Guy Harris gravatar imageGuy Harris ( 2019-02-03 19:44:24 +0000 )edit

latest in windows 10 64.

dids201 gravatar imagedids201 ( 2019-02-03 23:21:10 +0000 )edit

is this "tcp fast open", hystart? etc, newer tcpip.sys with symbolic links? sorry i don't have any examples id think people would know if there was a difference

dids201 gravatar imagedids201 ( 2019-02-03 23:22:36 +0000 )edit