Skip to main content

pktmon - tcpdump for Windows

Here's a great series of articles by Rickard Nobel on using PKTMON.

Filter basics

Example: tcpdump like cli for Mikrotik MNDP packets

# clear filters
pktmon filter remove

# add MNDP filter
pktmon filter add Mikrotik_MNDP -t UDP -p 5678

# list interfaces available to capture on
pktmon list

# replace ## below with the interface number you wish to run the capture on
pktmon start -c -m rt -s 16 --comp ##

Example: tcpdump like cli for LLDP packets

# clear filters
pktmon filter remove

# add MNDP filter
pktmon filter add "LLDP" -d 0x88cc

# list interfaces available to capture on
pktmon comp list

# replace ## below with the interface number you wish to run the capture on
pktmon start -c -m rt -s 16 --comp ##

# same as above but removing the lines containing PktGroup if desired
pktmon start -c -m rt -s 16 --comp ## | Select-String -Pattern "PktGroup" -NotMatch

Example: CDP + LLDP