The Promiscuous Mode of the network adapter is that a machine can receive all the data streams passing through the network adapter, regardless of whether the target address is another one. This is used by network administrators to diagnose network problems, but is also used by unauthenticated people who want to listen to network communication (which may include passwords and other sensitive information. A non-Route Selection node can only be in the same conflict domain (for Ethernet and wireless LAN) in hybrid mode) internal monitoring communicates with other nodes or rings (for the card ring or FDDI), which is why network switching is used to combat malicious hybrid modes. In hybrid mode, all packets passing through the network card are received, including packets not sent to the local machine. By default, only packets (including broadcast packets) sent to the local machine are transmitted to the upper-Layer Program. All other packets are discarded. To put it simply, the hybrid mode means that the network card can accept all the data streams that pass through it, no matter what format or address. The specific address Forwarding is performed on the MAC layer after the data is received. Generally, packet capture tools, such as ethereal and sniffer, need to place the NIC in the hybrid mode and use the software Winpcap. Winpcap is the next free and public network access system on windows. Winpcap is developed to provide win32 applications with the ability to access the bottom layer of the network. For a broadcast Hub, if PC1, PC2, and PC3 are connected to the same Hub, when PC1 sends a packet to PC3, the Hub broadcasts the packet, so PC2 can actually see this package, but usually it will discard the package sent to PC3, but if it is in mixed mode, PC2's NIC driver will not discard this package, instead, the package is sent to the upper-layer drivers and applications. To put it simply, the network adapter's hybrid mode is provided for network analysis.