Search code examples
ndis

What is Microsoft's nm3.sys (Netmon Lightweight Filter Driver) in the NDIS network stack?


I was analyzing a Windows 11 crash dump, and got the output for the ndiskd.netreport, and in the graphical network stack of output, I noticed nm3.sys NDIS filter driver right below the WFP Native MAC Layer LightWeight Filter. And oddly enough, this is a driver that has not got updated for a very long time (2010), and its description is NDIS 6.0 Monitoring driver, which is very vague.

So what's the point of this NDIS filter driver and why is it so low on the stack?


Solution

  • nm3.sys is not part of the OS; it is installed as part of Microsoft Network Monitor. It's a packet capture program. It still works, but it has been discontinued, so we recommend you replace it with Wireshark.