How does Network Monitor interpret the protocols in a trace that has been captured?
A. Network Monitor includes protocol parsers that look at and interpret key items within the raw data to interpret some of the most common protocols. As new standards and implementations evolve, there will be certain protocols for which NetMon does not contain parsers. Individuals can write parsers for these protocols, or other companies may write some of these parsers (which can be found on the Internet). Some additional parsers are included in the Microsoft Resource kits.