Windows 10下如何定位持续发送固定IP ICMP包的进程?
Got it, let's track down which process is sending those ICMP packets to that fixed IP on your Windows 10 machine. I've got a few tried-and-true methods for you, ordered from easiest to more detailed:
Method 1: Use Windows' Built-in Resource Monitor
No extra tools needed—this is the quickest way:
- Press
Win + R, typeresmon, and hit Enter to launch Resource Monitor. - Switch to the Network tab.
- Scroll down to the Network Activity section. If you don't see the ICMP column, right-click the table header and check ICMP to enable it.
- This table will list every process sending ICMP packets, along with their target IPs. Just match the IP you saw in Wireshark, and you'll have your culprit process right there.
Method 2: PowerShell Command-Line Tracking
If you prefer working in the terminal, PowerShell gives you precise control:
- Open PowerShell as an administrator.
- Run this command, replacing
<target-ip>with the fixed IP from Wireshark:
This will return the Process ID (PID) of the process sending ICMP to that IP.Get-NetICMPStatistics -DestinationAddress <target-ip> - To get full details about the process, run:
Alternatively, you can use the classicGet-Process -Id <pid-from-previous-step>netstatcommand:
Find your target IP in the results, note the PID, then run:netstat -ano -p icmp
to get the process name and path.tasklist /fi "PID eq <pid>"
Method 3: Wireshark + Process Explorer for Advanced Tracking
If the ICMP packets are sent intermittently and you need to correlate them with live process activity:
- Grab Process Explorer (a free Sysinternals tool from Microsoft—no installation required).
- When you catch the target ICMP packet in Wireshark, right-click it and select Follow > ICMP Stream. Jot down the packet's timestamp for reference.
- In Process Explorer, go to View > Lower Pane View and select Network Connections. The lower pane will show all active network connections, including ICMP. Look for your target IP here, and the upper pane will highlight the associated process.
- You can also right-click the process in Process Explorer and select Properties to dig deeper—check its file path, digital signature, or startup arguments to confirm if it's legitimate.
Quick Tips for Suspicious Processes
If you find an unknown process sending ICMP packets:
- Right-click the process and select Open File Location to check where it's stored. Verify if the file has a valid digital signature from a trusted publisher.
- Run a scan on the file with Windows Defender or your preferred antivirus tool to rule out malware.
- Check if the process is set to start automatically at boot—use Task Manager's Startup tab or
msconfigto review and disable it if needed.
内容的提问来源于stack exchange,提问作者ZXY
相关产品推荐
相关产品推荐

