BANDWIDTH LENS 0.1.0 — WINDOWS PORTABLE
Windows 10 / Windows 11, x64

GET STARTED
1. Extract the ZIP into a folder.
2. Double-click BandwidthLens.exe.
3. Approve the Windows administrator prompt.
4. Start a download, stream, file copy, or other network activity.
5. The highest combined bandwidth consumer appears first. Click Download or
   Upload to sort in that direction. Select a row for service and endpoint details.

There is no installer. No Python, .NET package, Npcap, browser, account, Internet
service, or third-party runtime is required. The executable uses Windows system
DLLs. Closing its window stops the monitor. Delete the file to remove the app.

This is a newly built, unsigned initial release. Its executable structure and
core logic were tested, but live capture and the native UI have NOT been run on
a Windows machine in the build environment. Windows may display an unknown-
publisher / reputation warning. The complete source is supplied separately.

WHAT IT SHOWS
- Program name and PID.
- Download, upload, and combined rate; Mbps or KiB/s.
- Downloaded/uploaded bytes since launch or Reset.
- Hosted Windows services and the executable path.
- Up to 12 retained remote endpoints per process, including IPv4/IPv6, TCP/UDP.
- A recent activity graph, text search, active-only filter, and CSV export.
- Lost-event and decode-error counters. Nonzero values mean counts may be incomplete.

HOW TO USE IT
- Click any column heading to sort. Default: highest combined rate first.
- Search matches program, PID, service name, display name, and path.
- Pause view freezes the displayed data; capture continues. The first resumed
  rate averages the interval since the view was paused.
- Reset clears this session's totals and resumes the view.
- Export CSV saves the currently filtered process rows as UTF-16 CSV, readable
  by Excel. Exported rate columns use bytes/second regardless of display units.
- Include loopback also counts traffic between local applications.

SERVICE ATTRIBUTION
For a service with its own PID, its host's bandwidth is easy to identify.
When multiple services share svchost.exe, the app lists every hosted service and
marks the PID as shared. It cannot truthfully assign that PID's bytes to one of
the hosted services. It does not stop services or alter their hosting model.

MEASUREMENT SCOPE
The app reads native Windows ETW TCP/UDP Send/Receive activity, using the PID in
the network event. It does not use disk-inclusive process I/O counters.

It measures this computer only, across all adapters. It includes both LAN and
Internet traffic. Rates are not a guaranteed percentage of your ISP link speed.
VPN encapsulation, protocol layers, offload, ETW buffering, and local-to-local
traffic can make values differ from Task Manager's adapter totals. Loopback is
excluded by default. Non-TCP/UDP protocols are outside the Windows collector.
Rates can appear in bursts because the tracing buffers flush periodically.

The app retains at most 2,047 named process records per session. If that fills,
additional traffic is counted in "Unattributed / process history limit" until
Reset. Endpoint details are bounded; process/session byte totals continue.
Very short-lived processes may appear only as a PID. PID-reuse detection resets
that displayed row's totals; overall session totals retain the earlier bytes.

PRIVACY / CHANGES TO YOUR PC
The app reads event metadata and process/service information. It has no cloud
connection or telemetry, opens no listening socket, stores no packet contents,
and makes no firewall, registry, service, or autostart changes. CSV is written
only when you select Export. It creates one temporary, uniquely named ETW session.

IF CAPTURE DOES NOT START
- Make sure this is 64-bit Windows 10 or 11 and that elevation was approved.
- Close other tracing applications and retry if Windows has no free system
  tracing sessions. The startup message includes the Windows error number.
- If the app is forcibly terminated, its ETW session can remain until reboot.
  To clean up only that session, use an elevated command prompt:
      logman query -ets
      logman stop "BandwidthLens-<exact PID and suffix shown by query>" -ets
  Copy the exact BandwidthLens session name from the query; do not stop others.

FIRST-RUN CHECK
Start a large browser download and sort by Download; the browser PID should rise.
Upload a file and sort by Upload. Compare the direction and approximate rates
with Windows Resource Monitor. Select a service-host PID and verify its services
against Task Manager's "Go to service(s)" view. Close the window and confirm its
BandwidthLens trace is gone with "logman query -ets" if needed.

NOT AFFILIATED WITH MICROSOFT OR SYSINTERNALS
This is a separate utility inspired by TCPView's portable desktop workflow.
