How to convert Microsoft Network Monitor `.cap` file to `.pcap` or `pcapng`?

4.4k Views Asked by At

When I tried to use editcap to convert .cap to .pcap, I got:

'editcap: The capture file being read can't be written as a ".pcap" file.'

The .cap file generated by Microsoft Network Monitor looks very special, which contains application and other information. How to convert it to something similar to the ".pcap" generated by Wireshark.

1

There are 1 best solutions below

4
On BEST ANSWER

I think you'll have to use Wireshark itself to convert the file as you seem to have run into Wireshark Bug 15482 - editcap can't convert a NetMon 2.x capture file to pcapng, even though Wireshark can do it.

Unfortunately, there has been no traction with resolving that bug in over a year, so it doesn't appear to be a high priority bug or on anyone's radar. You can try voting for the bug or even better - submitting a patch to fix it if you're able to.