Configuring Wireshark to ID Local Apps Downloading Thru svchost

asked 2022-07-19 22:35:08 +0000

Is there a way to config WIRESHARK to display apps/programs on my PC that are using svchost.exe to download. I have Win10 set to pause updates for a month and have configured as many apps as I can to not automatically download updates or backup data remotely, yet I just went thru over an hour where "something" downloaded 600MB via svchost. I have Norton 360 running and Malwarebytes and just ran both doing full system scan and all is "clean". I did run netstat -b in elevated cmd prompt but could not find culprit there (difficult to look through anyway). Thanks!

answered 2022-07-20 18:53:46 +0000

Wireshark cannot currently do this, but such capture can be made using the built-in Windows capture tool PktMon.

The tool is available in Windows 10 builds 19041 (20H1) or later

Thanks a ton! Looking at the tool and commands right now.

NCBlacksmith gravatar imageNCBlacksmith ( 2022-07-20 22:10:00 +0000 )edit

