Archive Pages Design$type=blogging

Monitoring Windows Network Activity

Today's tip is on monitoring network activity on Windows XP... Our main focus of monitoring this activity is to ensure that the applic...

Today's tip is on monitoring network activity on Windows XP... Our main focus of monitoring this activity is to ensure that the applications accessing the internet are only programs that we are aware of, and have "authorized" via firewall rules... After any virus, spyware, or adware cleanup, it is also a good idea to make certain that nothing was missed or reinstalled after the cleanup which is still accessing the network...

While Windows XP ships with a few utilities for displaying current network connections and process information, it lacks a realtime monitoring application... The application we'll be using today is a freeware utility from SysInternals called TCPView... While there are other more powerful monitoring and packet-capture applications, I prefer TCPView for it's simplicity and portability... It does not require an install, and can be run directly from a USB flash drive...

TCPView can be downloaded from the SysInternals website by clicking here...

After downloading the archive, unzip the files to a location of your choice and launch the Tcpview.exe program... The window displayed should look similar to the one shown below...


The display will show all processes with TCP and UDP endpoints, the protocol in use, the local address and port number, the remote address and port number, as well as the connection's current state... To view only connected endpoints, uncheck "Show Unconnected Endpoints" from the Options menu...

As new connections are created, the background of the line item will turn green until the next refresh cycle... Items that change state from the previous refresh will be displayed with a yellow background, and recently destroyed connections will appear with a red background...

To view detailed process information on a specific item, right click the desired item and select "Process Properties"... The full path and command line for the application will be displayed...

Finally, to terminate the connection of a listed item, you can simply right-click on the item and select "Close Connection"... This option is only available for processes with connected endpoints...

If you have any questions on today's tip, please leave a comment...

COMMENTS

الاسم

ASA CCNA Flashcards CCNA Interview Q\A CCNA Labs Cheat Sheets cisco certification Cisco IOS Ethernet Cabling Free Network Tools Ftp Links GNS3 Tutorials IPv6 - Introduction LAB 1 LAB 2 Linux Router Networking Online Videos Packet Tracer Posters Qemu Softwares subnet mask TestInside tips-tricks Ubuntu Video Tutorials Windows 7 Networking Youtube Vids
false
rtl
item
virtualization cloud computing security privacy data blatform: Monitoring Windows Network Activity
Monitoring Windows Network Activity
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4T3NpJd1ayKWP0bxzpTBVrh4Ule1O8zSjvtNQCCBSZ2faTGMoRf1xzazrpRC_-W_UWtSxTN2apPHzjlaGh57nTgoSo4y5hJCxxwqhkoU2JuAsTttQQ35NKdmRCVmA529aKESZfs3nlws/s640/tip-9-1.jpg
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4T3NpJd1ayKWP0bxzpTBVrh4Ule1O8zSjvtNQCCBSZ2faTGMoRf1xzazrpRC_-W_UWtSxTN2apPHzjlaGh57nTgoSo4y5hJCxxwqhkoU2JuAsTttQQ35NKdmRCVmA529aKESZfs3nlws/s72-c/tip-9-1.jpg
virtualization cloud computing security privacy data blatform
http://cloud-virtualization3.blogspot.com/2010/04/monitoring-windows-network-activity.html
http://cloud-virtualization3.blogspot.com/
http://cloud-virtualization3.blogspot.com/
http://cloud-virtualization3.blogspot.com/2010/04/monitoring-windows-network-activity.html
true
4356106142092226719
UTF-8
Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago