Skip to content

Network Activity

Ricardo Esquivel edited this page Sep 17, 2026 · 28 revisions

Q: Which apps are talking to the network/internet?

Q: Which servers/URLs are they using, and how much data is being transferred?

Q: What code is responsible!?

A: MSO-Scripts is uniquely able to answer these questions and more!

Short Story

  • MSO-Scripts gathers and correlates key ETW events from common network providers:
    TCP/IP, WinSock, WinHTTP, LDAP, WinINet, URLMon, Chromium, DNS

  • It also stitches together symbolic call stacks across various threads to identify the native code which originated each network connection.

  • A WPA add-in organizes the data into a timeline and activity table.

Quick Start

  • Download and unzip a Release of MSO-Scripts.
    (If you cloned the repository, you'll need to build the WPA plug-in.)
  • MSO-Scripts\BETA\TraceNetwork Start
    Launch the app. Exercise the code.
  • MSO-Scripts\BETA\TraceNetwork Stop
  • MSO-Scripts\BETA\TraceNetwork View

List all options:

  • MSO-Scripts\BETA\TraceNetwork -?

Important

If the PowerShell script does not run, you can instead run the CMD/Batch script:
MSO-Scripts\BETA\TraceNetwork.BAT ...
See: What if I can't run PowerShell scripts in my environment?

Note

MSO-Scripts has two scripts named TraceNetwork, one in the root folder and one in the BETA folder.
These two scripts collect the same data, but BETA\TraceNetwork View uses a special WPA plug-in to easily analyze network activity.


Long Story

Windows and many of its applications, such as Microsoft Office, use WinHTTP, WinINet, and related services to communicate via network/internet.
Major browsers such as Chrome and Edge use Chromium to communicate, as does the WebView2 platform.
These and most every other network service are built on top of WinSock, which transfers data via the TCP/IP layer.

---
title: Simplified Network Layer Diagram
---
flowchart TD;
   WinSock-->TCP/IP
   WinHTTP-->WinSock
   WinINet-->WinSock
   LDAP-->WinSock
   Chromium-->WinSock
   TCP/IP-.->Network{{Network / Internet}}
Loading

MSO-Scripts gathers the essential ETW events from TCP/IP, WinSock, WinINet, WinHTTP, Chromium, and other providers to create (using a custom WPA plugin) a detailed, correlated timeline and table of network activity:

  • Server / DNS Name(s)
  • URL
  • IP Address & Port
  • Protocol & Method
  • Bytes sent/received
  • Start Time & Duration
  • Process & Threads
  • Geolocation, and more...

WPA Network View

Note

Network traces collected on a pre-Windows 10 OS may not work with the custom plug-in loaded by BETA\TraceNetwork View ... In that case use the non-BETA version of TraceNetwork, which exposes network activity in a different way.

Chromium (Chrome & Edge browsers, and WebView2)

TraceNetwork collects and analyzes Chromium activity beginning with release 1.0.1.0 (September 2026).

  • Optional: Close the Edge / Chrome Browser and kill all its processes:
    TaskKill /f /im MSEdge.exe or Chrome.exe, etc.

  • MSO-Scripts\BETA\TraceNetwork Start -JS
    Optional -JS is for JavaScript Symbol Resolution

    Launch and exercise the browser.

  • MSO-Scripts\BETA\TraceNetwork Stop

  • MSO-Scripts\BETA\TraceNetwork View

Chromium network activity shows up in two graphs/tables:

  • The main NetBlame URL Table with: Protocol = Chromium
  • The NetBlame Chromium Requests table, with Chromium-specific details

Symbolic Call Stack Attribution

Each event which creates a network request registers the flow of code which led to that event, i.e. a call stack (stackwalk) on that execution thread. However, network events are usually scheduled on one execution thread to occur soon thereafter on another thread. There may be many threads involved in the scheduling chain.

MSO-Scripts captures the activity of the Windows and Office Thread Pools, and stitches them together to reveal the chain of events, even as far back as WinMain (app launch). To view these execution stacks, enable any of these four columns in the "NetBlame URL Table" tab via WPA's View Editor (ctrl+E):

  • First Stack: the earliest available call stack which initiated the network request, nearest to WinMain.
  • Last Stack: the call stack of the actual network request (often dispatched in a pool thread).
  • Middle Stacks: an aggregation of call stacks (if any) between the First and Last Stack.
  • Full Stacks: the aggregation of all call stacks leading to the network request, First + Middle + Last.

Note

Stackwalking works on all platforms: Native (C, C++), Managed (C#, CLR with TraceNetwork Start -CLR), and JavaScript (Chromium/V8 or Chakra with TraceNetwork Start -JS). However, stack chaining works only with Native code using the Windows and/or Office Thread Pools.


How to Get the 'NetBlame' WPA Network Plug-in

  • If you downloaded and unzipped a Release of MSO-Scripts, then you're good to go!

    Simply run: MSO-Scripts\BETA\TraceNetwork View

    TraceNetwork will automatically find the plug-in in this folder: MSO-Scripts\BETA\ADDIN

  • If you installed MSO-Scripts in one of these ways:

    ...then you will need to build the 'NetBlame' plug-in:

    1. Ensure that the .NET developer platform (dotnet.exe) is installed.
    2. On a command-line within the NetBlame folder, run: dotnet.exe build -c Release

    TraceNetwork will automatically find the plug-in under this folder: MSO-Scripts\src\NetBlame\bin\Release

  • See detailed build guidance at: NetBlame/ReadMe.md


Credit

Information in the GeoLocation column comes from IP-API, which provides 45 free queries / min.

See Also


MSO-Scripts: Introduction
      MSO-Scripts: Introduction (Video Link)

Clone this wiki locally