windows

unexpected shutdown


capture => wireshark

windows  2016


netsh trace show interfaces
netsh trace start capture=yes captureinterface=XX

netsh trace start capture=yes captureinterface=XX IPv4.Address=X.X.X.X tracefile=c:\temp\capture.etl persistent=yes
netsh trace start capture=yes tracefile=c:\temp\capture.etl maxsize=512 filemode=circular overwrite=yes report=no correlation=no IPv4.SourceAddress=(192.168.1.55,192.168.1.5) IPv4.DestinationAddress=(192.168.1.55,192.168.1.5) Ethernet.Type=IPv4


netsh trace start capture=yes tracefile=c:\temp\capture.etl maxsize=512 filemode=circular overwrite=yes report=no correlation=no

netsh trace stop

C:\tools\etl2pcapng\etl2pcapng.exe C:\temp\capture.etl capture.pcapng

netsh trace stop
Etl2pcapng.exe capture.etl newfile.pcapng 

windows 2019 =>

pktmon filter add -t tcp syn -p 3389

pktmon start --capture

pktmon stop

pktmon pcapng c:\Windows\System32\PktMon.etl -o C:\temp\new_file.pcapng

Remove-Item c:\Windows\System32\PktMon.etl

pktmon filter remove 1

For /F %s in ('dir /b *.dll') do regsvr32 /s %s