Capture and Monitor Network Connections on Mac
TinyShield watches network connections from apps and macOS services. It groups each destination under the app that created the connection.
TinyShield captures connection details such as the app, hostname, IP address, port, direction, status, and location. It is not a packet inspector and does not show decrypted HTTPS request or response content.
Expand an app to see the hostnames and IP addresses it contacted.
1. Benefits
- ✅ See which Mac app opened each connection.
- ✅ Group domains and IP addresses under the app that used them.
- ✅ Read hostnames instead of guessing from an IP address.
- ✅ Find traffic from browsers that use DNS over HTTPS.
- ✅ Check whether a connection is active, allowed, or blocked.
- ✅ Search by app, domain, or address.
- ✅ Keep monitored data on your Mac.
2. Start monitoring
- Install and approve the TinyShield Network Extension.
- Open TinyShield.
- Keep Allow All selected while you learn the normal traffic on your Mac.
- Open the app or website you want to check.
- Find the app in the TinyShield list.
- Select the arrow beside the app to see its destinations.
- Expand IP Addresses when a hostname is not available.
The list updates as new connections arrive. Use the time menu to focus on recent activity.
3. Find useful traffic
- Use the search field to find an app, domain, or IP address.
- Select a row to inspect its status and destination details.
- Open the Map to see the destination country or region.
- Right-click a row when you want to block it or show it on the map.
- Clear old records when you want a clean view for a new test.
4. Why a hostname may be missing
TinyShield learns hostnames from DNS and connection information. A hostname may be missing when an app connects directly to an IP address, uses cached data, or does not send enough name information.
The IP address still appears under the app. You can use it for blocking or GeoIP lookup.