How to Use Sniffnet to Monitor Network Traffic on Windows 11

8 min read

Help Desk Geek is reader-supported. We may earn a commission when you buy through links on our site. Learn more.

An unexplained bandwidth spike on your Windows 11 PC can leave you wondering which connection is busy. Sniffnet lets you watch traffic on the adapter you choose, then narrow down what was active during the spike.

What Is Sniffnet?

See what your computer sends and receives

Sniffnet is a free desktop app that captures traffic from a selected network adapter and turns it into readable summaries. It can show traffic volume, hosts, services, and, when identification is available, the program associated with a connection.

If you only need to see which running app is using bandwidth right now, press Ctrl + Shift + Esc and check the Network column in Windows Task Manager’s Processes tab. Use Sniffnet when you need to inspect the connections behind that activity. A host name tells you where traffic went; by itself, it does not prove which program sent it or whether the traffic is harmful.

Prerequisites

  • A Windows 11 PC, or a Mac for the macOS steps below.
  • Permission to install an app. Windows users also need permission to install the Npcap capture driver.
  • An active Wi-Fi or Ethernet connection and a website you can open to generate test traffic.
  • Enough free disk space if you plan to save an optional PCAP capture.

Step-by-Step Guide

Windows 11: Install Sniffnet and capture your first traffic

  • Check your processor type. Open Start > Settings > System > About. Under Device specifications, find System type. Most Intel and AMD PCs need the x64 Sniffnet installer; Windows-on-Arm PCs need ARM64. The page should state whether your system uses an x64-based or ARM-based processor.
Windows 11 Settings > System > About with the System type field highlighted
  • Download Npcap. Visit the official Npcap site and download its current Windows installer. Sniffnet needs Npcap because Windows does not give it the packet-capture interface it needs on its own.
Npcap download section with the Npcap 1.89 installer link.
  • Install Npcap. Open the downloaded installer, approve the Windows permission prompt, and follow the setup screens. When the installer offers WinPcap API-compatible Mode, select it, then finish setup. Restart Windows if the installer requests it. Install Npcap; the older WinPcap package is not required.
Npcap installation options with WinPcap API-compatible Mode selected.
  • Download the matching Sniffnet installer. Open the official Sniffnet releases page and expand the latest release’s Assets list if needed. Download the Windows x64 MSI for an x64-based PC or the Windows ARM64 MSI for an ARM-based PC. The project may also list an x86 installer for 32-bit Windows, which is not the usual choice for a Windows 11 PC. The result should be an .msi file in Downloads.
Sniffnet v1.5.1 release assets with Windows x64 and ARM64 MSI downloads.
  • Install and open Sniffnet. Double-click the downloaded MSI, approve the Windows prompt, and complete the installer. Open Start, search for Sniffnet, and launch it. You should reach its adapter selection screen.
Windows 11 Start search showing Sniffnet with its spy icon and Open action.
  • Choose the adapter carrying your traffic. Select the Wi-Fi adapter if you are connected over Wi-Fi, or the Ethernet adapter if you use a network cable. A USB Wi-Fi adapter or docking station may appear under a less familiar name. If a VPN is connected, its virtual adapter may carry the traffic you want to inspect. Select the adapter in the left-hand list on the initial page, then use the start-monitoring control. See the project’s data-source guide if the layout differs.
Sniffnet data-source selection with the active Wi-Fi adapter selected and the Start button.
  • Confirm that capture works. Open a familiar website in your browser, then return to Sniffnet. Its traffic overview should show a short rise in activity. If the view stays empty, use the no-traffic fix below before drawing conclusions about the connection.
Sniffnet traffic overview after a short website visit, with the change in traffic highlighted
  • Inspect the spike. In Sniffnet’s traffic views, look at the hosts and services active during the rise. Check for a program name where the installed version provides one. Program identification can help explain a connection, but it may be unavailable or incomplete for some traffic. Match the time and amount of traffic to what you were doing on the PC.
Sniffnet report showing hosts, services, and an associated program where identification is available
  • Narrow the view with filters. For a capture filter, return to the initial page and enter a Berkeley Packet Filter expression in its filter field before starting a new capture. Use the project’s filter guide for syntax; leave the field empty for an unfiltered baseline. Clear the filter afterward to restore the full view. An unfamiliar host is a lead to investigate, not proof of malware: updates, cloud sync, browser tabs, and security software can all contact servers you do not recognize.
Sniffnet capture filter with Filter traffic selected and tcp in the BPF expression field.

macOS: Install Sniffnet and confirm traffic

Npcap is a Windows dependency. On a Mac, use the project’s official disk image. Its macOS installation guide distinguishes that package from alternative installations such as Homebrew, which need an administrator-privileged launch (sudo sniffnet) for capture.

  • Check the Mac’s processor. Open the Apple menu > About This Mac. Note whether it shows an Apple chip or an Intel processor. You will use that detail to choose the matching download.
About This Mac window with the Apple chip or Intel processor information highlighted
  • Download the matching macOS build. Open the Sniffnet releases page, expand the latest release’s Assets, and choose the macOS package marked for Apple silicon or Intel, as appropriate. You should find the downloaded package in Downloads.
Sniffnet v1.5.1 release assets showing Apple silicon and Intel macOS disk images.
  • Install and open the app. Open the downloaded disk image and drag Sniffnet into Applications. Open it from that folder. If macOS blocks launch, follow the project’s installation guide and macOS’s displayed security instructions for the verified official download; do not grant blanket permissions to an unknown package.
macOS Finder Applications folder with Sniffnet selected, using its official spy silhouette with hat and glasses app icon, not a blue globe
  • Select the active adapter and test it. Choose the adapter carrying your Wi-Fi or Ethernet connection, start monitoring, and open a website. Return to Sniffnet and look for a rise in the overview. If you use a VPN, also check its virtual adapter when the physical adapter does not show the traffic you expect.
Sniffnet Overview showing traffic volume and network host, service, and program summaries.

Configuration: Get a Useful View of a Bandwidth Spike

Keep the capture focused on the question you are trying to answer:

  • Start with the active adapter. If you switch from Wi-Fi to a Cat6 Ethernet cable, switch Sniffnet to the Ethernet adapter too. Monitoring an idle adapter will produce an empty or misleading view.
  • Create a short baseline. Watch the overview while the PC is idle for a minute, then open the app or website you suspect. Compare the traffic before and after.
  • Check the details. Look at hosts, services, and any program identification during the busy period. A program name is useful evidence, but Sniffnet may not identify every connection.
  • Apply one filter at a time. Narrow the view to a host or service that appeared during the spike, then clear the filter before checking another. This makes it easier to see whether the same traffic returns.

Optional: Save a short PCAP capture

A PCAP file stores captured network data for later inspection. It can contain sensitive details about connections and can grow quickly, so save one only when you need it.

  • Before starting capture, enable the PCAP export checkbox on Sniffnet’s initial page. Choose a filename and a private destination folder. The project’s PCAP export guide illustrates the control.
  • Start monitoring the relevant adapter and reproduce the spike briefly. PCAP export writes the captured traffic to disk; check the file size and contents before sharing it.
Sniffnet export settings with the export option selected, file name sniffnet.pcap, and directory C:\Users\User beside the browse control.
  • Stop monitoring when the short capture is complete. Delete PCAP files you no longer need from File Explorer or Finder, and empty the recycle bin or Trash if you need the space back. For a longer capture, check free space first; an external SSD is useful only if you have a reason to retain a large file.

Tips and Troubleshooting

Fix #1: Select the adapter that is actually in use

  • On Windows, open Settings > Network & internet and check whether Wi-Fi or Ethernet shows your current connection.
Windows 11 Settings > Network & internet showing the active Wi-Fi or Ethernet connection
  • Return to Sniffnet and select that adapter. If a VPN is active, test its virtual adapter as well.
  • Open a website and look for activity in the overview. If one adapter shows traffic and another does not, keep the one carrying the traffic you need to investigate.

Fix #2: Restart capture when the view shows no traffic

  • Clear any filters that could hide the activity.
  • Stop monitoring in Sniffnet, select the active adapter again, and start a fresh capture.
  • Load a new website page. If traffic appears now, the earlier view was filtered or listening on the wrong adapter. If nothing appears, check that the website loads normally before troubleshooting Sniffnet further.

Fix #3: Repair Npcap when the Windows adapter list is empty

  • Open Start > Settings > Apps > Installed apps and look for Npcap.
Windows 11 Installed apps page showing Npcap in the app list
  • If it is missing, download and install the current version from npcap.com. If it is present, run the current Npcap installer again to repair the installation. Select WinPcap API-compatible Mode during setup.
  • Restart Windows if prompted, then reopen Sniffnet. The adapter list should now populate.

Fix #4: Replace an installer that does not match your PC

  • Recheck Settings > System > About > System type on Windows, or Apple menu > About This Mac on macOS.
  • Return to the official Sniffnet releases page and download the package matching that processor. Run the new installer.

Wrapping Up

Choosing the adapter that carries your connection is usually the step that makes Sniffnet useful. A short website test confirms the setup before you investigate a real spike; if activity remains absent after checking the adapter and Npcap, look for a connection or driver problem. Treat unfamiliar hosts as clues to check, especially if traffic repeats while the PC is idle.

StepActionApplies To
InstallGet the matching Sniffnet build; install Npcap with compatibility modeWindows 11
InstallGet the build matching the Mac’s processormacOS
ObserveSelect the active adapter and load a websiteBoth
InvestigateCheck traffic views, filters, and optional short PCAP capturesBoth