In Windows, you cannot effectively analyze wireless frames, because you are unable to put the wireless NIC in "RF Monitor Mode" - that is the mode in which the wireless NIC can see ALL 802.11 frames in the air, not just ones intended for itself.
Historically, it's been an expensive proposition. There are some great tools out there like OmniPeek (which I use), the gold standard for Windows packet analysis. And for years, AirPcap Nx was the main NIC folks used for pcap'ing WLANs with Wireshark. Unfortunately, both options are pricey. And the AirPcap NX is no longer manufactured. You’d be lucky to find a used one on eBay. Linux and MacOS have been the only ways to cheaply get access to RF Monitor mode without spendy software and hardware, like Omnipeek and the AirPcap Nx.
But, not everyone uses Linux, or Mac OS. Fortunately, and fairly recently, there are more and more ways to get RF Monitor mode in Windows. Here are some relatively inexpensive options (NOT an exhaustive list) to perform an RF Monitor Mode wireless packet capture in Windows using relatively inexpensive hardware.
Acrylic Wi-Fi Pro ($45)
MetaGeek Eye P.A. now supports native Windows Monitor Mode! - (List of supported NICs) ($800.00 US) Also, will soon have support for WLAN-Pi!
OmniPeek ($2k +)
NEW! @WiFiNigel's blog on how to turn a WLANPi into an external packet capture device for Windows ($75 US) cab be purchased here.
OR, you could just get a Mac and do it natively. 😉
Here are some additional resources for wireless picture capture in Windows from @Ron_van_Kleunen:
* If anyone has additional relatively inexpensive options for this list please DM me @HeyEddie.
I don't know. Less than a grand? Less than $500? Please don't get all pedantic on me. 😉