WIP, Trace monitoring in Windows

·

1 min read

Table of contents

No heading

No headings in the article.

Today I tried these two commands.

netsh trace start capture=yes It requires to be run in administer mode. This commands starts the network capturing. The immediate output is an etl file. The netsh stop command(netsh trace stop) stops the capturing and creates a cap file in the end. The cap file is an archive file. When extracted, it has many info about the system info and the etl file.