← Back to context

Comment by Avamander

11 hours ago

Any ways to bring that to Linux or Windows? I've long yearned for a solution for this.

It supports ETW as an input format, but I (personally) haven't yet gotten my head around how to do the same.

My current worflow is capture with pktmon, then analysis in Microsoft Network Monitor to expose PID stuff.

I figure there /has/ to be a way to do it similarly in Wireshark, I just haven't found a how-to and haven't dug into it myself. Once I do (it's on my casual todo list) I'll do a writeup on that as well, since it'd be super useful.