USB Capture

Since v0.3.9, Netcap can also capture USB traffic, either live from an interface device or from a dumpfile encapsulating the USB traffic as PCAP(-ng).

For decoding USB traffic live, wireshark must be installed (used to set up an interface that exposes the USB traffic).

Use the net capture tool to extract USB audit records.

Read more about it in the documentation: USB Capture.