My two favorite programs for packet sniffing are both free:
- Wireshark (open source)
- Network Monitor (Microsoft)
I was pleasantly surprised today to find out that if you save a capture in Network Monitor, that you can open it in Wireshark. This gives the ability to look at the same data in both tools. Sometimes the way one tool interprets or displays the data is easier to understand when you are looking at something specific.