Whether it's a simple update check or direct access to cloud services, the number of programs that establish a remote connection is growing, but the user isn't properly informed about those connections. That's where secondary tools like LiveTcpUdpWatch, developed by Nirsoft, come in. While we've seen similar programs before, this one works through the Windows kernel, enabling a greater quantity and quality of data.
That a program checks for updates is common, but the question is: where does it connect? The data it sends and receives is a mystery to the end user.
Update systems and distribution chains are also tempting targets for malicious elements looking to steal information (of all kinds) or hold it hostage through ransomware campaigns.
And when it comes to Windows... let's say it could do a better job presenting low-level data. Fortunately, there are valuable resources out there, and one of the best is LiveTcpUdpWatch, created by Nirsoft.
All TCP and UDP Network Activity
The goal of LiveTcpUdpWatch is to present real-time data on all TCP and UDP network activity. Process name, protocol, local and remote ports, IP addresses (local and remote as well), received and sent packets, date and time of each connection, executable location on the hard drive, and the total transferred in bytes are some of the categories the program reports by default.
Those who closely follow Nirsoft's software will probably notice some similarities with CurrPorts or NetworkTrafficView. The difference is that CurrPorts doesn't register UDP packet sending, and NetworkTrafficView is a sniffer that requires certain conditions to work. In contrast, LiveTcpUdpWatch works with the event tracing API and gets data from the Windows kernel.
LiveTcpUdpWatch is compatible with all Windows versions from XP, in both 32 and 64 bits. It doesn't have any installer (a classic for Nirsoft), and from Windows Vista onward the program needs administrator privileges to work properly, but that shouldn't become a major problem unless the environment is protected in some way and doesn't allow elevating processes.