Digging the .ETL file – network packets file for TCP connection

Cheat Code
TCP.port==1433

So we have .ETL file from previous netsh session, what can we do with it?
I installed Microsoft Network Monitor 3.4 (download here) – Microsoft why Archive such amazing tool!? 😦 –
Once it’s installed I launch it
Then the usual File -> Open -> Capture… and select the .etl file
Set the “Parser Profile”

Microsoft Network Monitor – Setup Network Parser

Once that’s done, we can setup the filter “tcp.Port == 1433” at the Display Filter area and click “Apply”

Microsoft Network Monitor – Applying TCP Port Filter

Voila!
now we can focus on tracing our packets

Image by nightowl from Pixabay

Published by Feivel

We love to travel!

Leave a comment

Design a site like this with WordPress.com
Get started