airbus-cert / Winshark

A wireshark plugin to instrument ETW
Apache License 2.0
535 stars 59 forks source link

No physical interfaces after Winshark installation #5

Closed killthepatate closed 2 years ago

killthepatate commented 2 years ago

Hello,

Great work, i can now put together network trafic and processID. I use netsh and logam.

But i have one problem, i can't see my physical network adapter when i launch wireshark and i'm not able to lauch a capture on this network adapters.

Do you have a solution in order to see it ?

Thank you

citronneur commented 2 years ago

Hi Killthepatate,

Sorry but it's not possible. In Winshark we are replace the library which is in charge of network capture, by one that can do ETW capture.

You have to install a normal Wireshark in another location.

Have a nice day,

Sylvain Peyrefitte