Repository navigation
Expand file tree
/
Copy pathMonitor-AppConnectios.ps1
More file actions
65 lines (57 loc) · 2.04 KB
/
Copy pathMonitor-AppConnectios.ps1
File metadata and controls
65 lines (57 loc) · 2.04 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
# Monitor-AppConnections.ps1
# Monitors TCP/UDP connections for a specified application or service
param (
[Parameter(Mandatory=$true)]
[string]$ProcessName,
[int]$Interval = 5, # Time between checks in seconds
[switch]$IncludeUDP
)
# Function to get process ID from process name
function Get-ProcessId {
param ([string]$Name)
$process = Get-Process -Name $Name -ErrorAction SilentlyContinue
if ($process) {
return $process.Id
}
Write-Host "Process $Name not found." -ForegroundColor Red
exit
}
# Get initial process ID
$pidId = Get-ProcessId -Name $ProcessName
Write-Host "Monitoring connections for $ProcessName (PID: $pidId)..."
Write-Host "Press Ctrl+C to stop monitoring."
# Main monitoring loop
try {
while ($true) {
# Clear screen for better readability
Clear-Host
Write-Host "Monitoring $ProcessName (PID: $pidId) - $(Get-Date)"
Write-Host "----------------------------------------"
# Get TCP connections
Write-Host "TCP Connections:" -ForegroundColor Cyan
$tcpConnections = Get-NetTCPConnection -OwningProcess $pidId -ErrorAction SilentlyContinue
if ($tcpConnections) {
$tcpConnections | Format-Table -Property LocalAddress, LocalPort, RemoteAddress, RemotePort, State, CreationTime -AutoSize
} else {
Write-Host "No TCP connections found."
}
# Get UDP endpoints if requested
if ($IncludeUDP) {
Write-Host "UDP Endpoints:" -ForegroundColor Cyan
$udpEndpoints = Get-NetUDPEndpoint -OwningProcess $pidId -ErrorAction SilentlyContinue
if ($udpEndpoints) {
$udpEndpoints | Format-Table -Property LocalAddress, LocalPort, CreationTime -AutoSize
} else {
Write-Host "No UDP endpoints found."
}
}
# Wait for the specified interval
Start-Sleep -Seconds $Interval
}
}
catch {
Write-Host "Error occurred: $_" -ForegroundColor Red
}
finally {
Write-Host "Monitoring stopped."
}