

This is a huge one in my book, this functionality was brought over from the Npcap change. Monitor mode support for Windows wireless analysis.A while back I did a look at how Winpcap interacts with the NIC cards and captures packets, Even though Npcap is based off Winpcap I am curious to see if that underlying interaction has changed (more to come on that, or I’ll just update this blog post later on with my findings) Npcap is actually part of the NMAP project which while Npcap is build of Winpcap Npcap gets a little more love in regards to up updates and being actively worked on. WireShark v3 for Windows now ships with Npcap as opposed to Winpcap that we have been used forever now. However outside of the new features, there is one major under the hood change this feature introduces. Recently, Wireshark dropped a major release which adds a few cool features (some new and some old).
