In this article
- What does Windows Telemetry Inspector show?
- How does ETW capture work?
- Download and first launch
- Investigate a connection in five steps
- Privacy: analyse locally, share captures deliberately
- What can you conclude from the results?
- Frequently asked questions
- Start with a clear question
- Sources and technical basis
Your PC is downloading something even though no browser window is open. Or you want to know whether a connection belongs to an update, a background service or an application. A destination IP rarely answers that on its own. Seeing the process, timestamp and service together gives you a more useful starting point.
My Windows Telemetry Inspector is a local diagnostic tool for Windows 11. It associates observed network events with processes and adds service and DNS information. You can investigate a specific question without sending your capture to an analysis service.
What does Windows Telemetry Inspector show?
The interface includes Live Traffic, process and service views, DNS observations, a timeline and summaries. Filters cover process name, PID, protocol, category, service and destination address. Selecting an event reveals the additional information available for that observation.
- Investigate one application: Filter its process and watch which destinations appear during a particular action.
- Understand background activity: Service names can help associate a connection with something like Windows Update.
- Compare activity over time: Record a short session and reopen it later rather than relying on a fleeting live view.
“Telemetry Inspector” does not mean every displayed connection is telemetry. Updates, time synchronisation and ordinary application traffic are also part of the observed network activity.
How does ETW capture work?
ETW means Event Tracing for Windows. The Inspector starts an event session and processes Windows kernel network events for TCP and UDP, including IPv6. Windows DNS Client events can be enabled too. The application adds process metadata and known services to this information.
The result describes connections and activity: timestamps, processes, local and remote addresses, ports and available byte counts. HTTPS is not decrypted and message contents are not inspected. The tool installs no custom kernel driver and changes no firewall rules.
Full capture needs administrator privileges. The interface can open without them, but the kernel provider may deny capture. The status explains the limitation and offers an explicit restart with elevated privileges.
Download and first launch
The project targets Windows 11 x64. Its GitHub Releases page contains the published EXE and its SHA-256 checksum. The self-contained build needs no separately installed .NET SDK.
Current builds are unsigned, so Windows may show a SmartScreen message. Download from the linked project and, if needed, compare the file checksum with the release information. In the directory containing the downloaded file, use this PowerShell command:
Get-FileHash .\WindowsTelemetryInspector.exe -Algorithm SHA256
A matching checksum confirms that the file matches that release asset. It does not replace code signing or a review of the program. If you prefer to build from source, the repository includes .NET 8 build instructions and a Windows verification checklist.
Investigate a connection in five steps
- Launch the Inspector and choose Start Capture. Check that the kernel provider is active and whether DNS observation is available.
- If privileges are missing, use the offered elevated restart and start capture again.
- Perform one identifiable action: open a website or check for updates, for example. Note its time.
- Filter Live Traffic by the expected process or destination. Select matching events and compare their process, service and DNS details.
- Stop capture. Use Record Capture or JSONL export to save data locally and reopen it later under Captures.
Short, focused captures are easier to interpret than hours of activity. Repeat the action if necessary and compare it with a period in which you do nothing. This gives you better evidence about which events are associated with your action.
Privacy: analyse locally, share captures deliberately
The Inspector does not use external geolocation or ASN lookups to enrich destinations. The diagnostic workflow requires no account and does not upload your capture to a cloud service. The network activity of the applications you observe naturally continues.
Saved captures default to %LOCALAPPDATA%\WindowsTelemetryInspector\Captures; you can change the folder in Settings. JSONL stores readable events that you can use in your own analysis.
These files may contain IP addresses, hostnames, usernames, process paths, command lines, service names and scheduled-task names. Review and redact an export before attaching it to a public issue or forum post. Screenshots of event details can expose personal information too.
What can you conclude from the results?
Categories use known process and service names together with DNS heuristics. A connection classified as “Telemetry” is an investigation lead, not proof of a particular transmitted payload. Confidence describes the rule-based classification; it is not a malware or privacy score.
DNS names can be missing because of encrypted DNS, cached answers or unavailable provider events. Process details may be incomplete after a process exits. A scheduled task close in time does not prove that it caused the connection.
Byte counters are diagnostic figures, not billing-grade measurements. Events can be missing, so check provider status and dropped-event indications. An empty table by itself does not establish that the computer has no network activity.
Frequently asked questions
Can it disable Windows telemetry?
The Inspector observes connections. It does not block destinations or change Windows privacy settings. Its observations can help you make more informed decisions afterwards.
Can I see the contents of an HTTPS connection?
No. The tool does not decrypt TLS. The SNI field provided in the export model is not currently collected either.
Does an unfamiliar IP address mean something is wrong?
That alone tells you very little. Consider process, service, timing and repeatable behaviour together. The Inspector provides context and does not replace a security investigation.
Start with a clear question
The downloads, source code and instructions are available on GitHub. Begin with a familiar application and a short session. That makes it easier to learn the views and interpret what you see.
If these observations make you reconsider your operating system, the Windows-to-Linux migration guide helps you prepare.
Sources and technical basis
The described features were checked against the project README and source code. Reviewed on 6 October 2026.