portfolio:/projects/AppWatch

Windows network observer

See which process
owns the traffic.

AppWatch connects live network activity to the Windows applications that created it—without losing sight of TCP, UDP, QUIC, or optional HTTP(S) details.

  • PlatformWindows 10 / 11
  • Releasev0.2
  • Built withRust + egui
Capture online Live traffic / all processes
AppWatch showing live per-process network traffic, transfer totals, connections, and running Windows applications
Live traffic view — select an application to inspect its connections and transfer activity.

What it watches

Packet capture, process attribution, and request inspection in one compact desktop tool.

01

Per-process traffic

Connect TCP, UDP, and QUIC activity to the application or process responsible for it.

02

Live measurements

Follow active connections, packet counts, and upload and download usage as they change.

03

HTTP(S) inspection

Optionally relaunch supported applications through the local proxy to inspect requests and responses.

04

Local history

Keep observed traffic history in SQLite for later review without requiring a remote service.

How it works

WinDivert captures network traffic and AppWatch maps packets back to running processes. HTTP(S) inspection uses a separate local proxy and only applies to applications launched through it.

RusteguiTokioWinDivertHyperSQLite
Target application
Raw network traffic→WinDivert→Process attribution
HTTP(S) traffic→AppWatch proxy→Remote server

Start a capture

HTTP(S) inspection is optional; packet monitoring works without routing applications through the proxy.

  1. 01

    Run as administrator

    Enable TCP, UDP, and QUIC packet capture.

  2. 02

    Choose a process

    Follow its connections and live transfer activity.

  3. 03

    Trust the CA if needed

    Use Proxy > Trust HTTPS certificate... for HTTPS inspection.

  4. 04

    Relaunch through the proxy

    Route the target through 127.0.0.1:8877 to inspect requests.

Requirements

AppWatch targets Windows 10 and 11. Packet capture needs administrator privileges; Rust is only needed when building the project yourself.

Operating system
Windows 10 / 11
Packet capture
Administrator
Build from source
Rust toolchain

Application detection

When relaunching an application, AppWatch looks for Chromium, Electron, CEF, Qt WebEngine, and WebView2 runtimes. It applies the appropriate proxy flags when recognised, but detection is best-effort because applications package these runtimes differently.

ChromiumElectronCEFQt WebEngineWebView2

Current limitations

HTTP/3 and QUIC payloads cannot currently be decrypted. HTTPS inspection only covers applications using the proxy, and some applications may ignore its configuration. Other protocols remain visible at network level, but their payloads are not decoded.

Build from source

Clone the repository and build the release workspace with Cargo.

git clone https://github.com/bivorzk/AppProcessWatcher.git
cd AppProcessWatcher
cargo build --release
cargo run --release -p apppw-ui

Current release · v0.2

Ready to inspect the wire?

Get the newest Windows build and release notes directly from GitHub.

Open Releases