In some cases, Microsoft support has requested netsh trace start provider=Microsoft-Windows-TCPIP; however, etl2pcapng currently doesn't support this GUID 2f07e2ee-15db-40f1-90ef-9d7ba282188a and causes the error Input ETL file does not contain an ndiscap packet capture. Such an ETL can be converted to text with netsh trace convert and it seems to have all the data we'd normally expect in Wireshark, but it is in a proprietary text format rather than pcap.