e
Jan. 4, 2023, 2:36 p.m. |

Embrace The Red embracethered.com

There is a combination of lesser known tools and techniques to capture and later decrypt SSL/TLS network traffic on Windows. This technique is neat because it does not require the installation of additional driver/software when capturing the traffic.
Technique, Tools and Steps It is quite straight forward and consists of:
Setting the SSLKEYLOGFILE environment variable to capture TLS session keys on target host Use netsh trace start to capture traffic (no need to install additional driver/software!

browser capture decrypt driver environment environment variable forward host install installation keys netsh network network traffic session software ssl start target techniques tls tools trace traffic variable windows wireshark

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Consultant

@ Auckland Council | Central Auckland, NZ, 1010

Security Engineer, Threat Detection

@ Stripe | Remote, US

DevSecOps Engineer (Remote in Europe)

@ CloudTalk | Prague, Prague, Czechia - Remote

Security Architect

@ Valeo Foods | Dublin, Ireland

Security Specialist - IoT & OT

@ Wallbox | Barcelona, Catalonia, Spain