Save a TCPView Connection Snapshot Without Treating Every Address as Suspicious
An unfamiliar address in a network tool does not explain why an application contacted it. Start with a specific question, such as which process has an endpoint while an authorised application performs a particular task.
Use TCPView from Microsoft's Sysinternals page on your own Windows PC or one you are authorised to inspect. Close unrelated private work where practical, and note the time and application action you plan to observe.
Preserve the process and endpoint together
TCPView lists TCP and UDP endpoints, local and remote addresses, TCP connection states and the owning process. It can also show a related service name. Keep those fields together rather than reporting only a remote address.
The tool normally resolves IP addresses to names. Use its toolbar or menu control to switch between resolved names and numeric addresses when needed, and record which representation you saved.
Microsoft documents a one-second default refresh interval, adjustable through Options, Refresh Rate. New endpoints are green, removed endpoints red and state changes yellow. These colours describe changes between refreshes; they are not trust ratings.
Perform the intended harmless application action and use the Save menu item to preserve the output window. Give the file a name that identifies the observation and time. If comparing before and during activity, save separate files rather than overwriting the first.
State what the snapshot can establish
Review whether the expected process appears with the relevant endpoint. A very short connection can occur between observations, so absence from one saved window is not proof that no connection ever happened.
Likewise, an endpoint list does not show the contents of a message or prove that a particular file was uploaded. Preserve the narrow observation and ask the application owner to explain an unexpected destination before drawing a conclusion.
Do not use the tool's connection-closing controls merely to see whether a row disappears. That would change the session being investigated and could interrupt work.
Keep the saved file private: local addresses, service names and destination names can reveal internal arrangements. A useful handover combines the selected process, state, address representation, time and user action, with any unresolved interpretation clearly identified.
Sources: Microsoft Sysinternals TCPView.