Packet capture from a Windows PC
Capture safely with pktmon or Wireshark, and read the basics: DNS queries and answers, the TCP handshake, resets vs no reply, and retransmissions.
- Level
- Advanced
- Length
- About 50 minutes
- Contents
- 3 lessons · 1 video · final exam
- Status
- Published · updated 1 Oct 2026
Skills you'll practise
- Take a short, focused capture with pktmon or Wireshark with the right approvals
- Read a DNS exchange and a TCP three-way handshake in a frame list
- Distinguish a TCP reset (active refusal) from no reply (silent drop)
- Recognize retransmissions as evidence of loss
Course outline
- 1.Packet capture from a Windows PCVideo · 5 min
- 2.Capturing safelyLesson · 14 min
- 3.Reading the basicsLesson · 16 min
- 4.pktmon step by step, and handing a capture overLesson · 14 min
- 5.Packet capture from a Windows PC: knowledge checkKnowledge check · 18 questions
- 6.Packet capture from a Windows PC: practical exerciseKnowledge check · 1 question
- 7.App fails instantly: resets in the captureScenario
- 8.Final exam8 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- Microsoft Learn: Packet Monitor (pktmon) overview
- RFC 9293: Transmission Control Protocol (TCP)
- RFC 1035: Domain Names: Implementation and Specification
- Wireshark User's Guide: display filters
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.