GlassWire is a Windows network monitor that records which applications contact the network, how much data they transfer, and which remote hosts receive those connections. Its graph turns network activity into a timeline, while the usage table groups traffic by application, host, traffic type, and country. It also controls application access through the firewall already built into Windows. It does not inspect every packet as a replacement for an antivirus scanner or a router-wide monitoring appliance.
Reading the graph
The traffic graph shows incoming and outgoing activity across a selected period. Clicking a peak identifies the applications and hosts active at that moment. The graph can separate traffic by application or publisher, which helps distinguish a browser download from a background updater. The history remains useful after the transfer ends because the user can return to the time when a sudden spike occurred.
A first-network-activity alert appears when a new application reaches the network. A clean installation produces many of these alerts while GlassWire learns the normal programs on the computer. The volume should fall after that learning period. A new alert identifies activity worth checking; it does not prove that the named program is malicious.
Usage on one PC
The usage table totals data for the computer where GlassWire runs. It can separate external Internet traffic from local transfers and set a warning near a chosen data allowance. This helps on a metered laptop connection because one large updater becomes visible by name.
The total is not the household’s complete Internet usage. A television, game console, phone, or another computer can consume data without appearing in this database. GlassWire may therefore show a number below the service provider’s meter even when both measurements are correct. Router statistics remain the better source for a whole-network quota.
Windows Firewall control
The firewall controls use the Windows Firewall API rather than installing an independent firewall engine. The Protect view lists applications and their remote hosts. Separate inbound and outbound controls can block one direction while leaving the other open. Turning off GlassWire’s firewall control does not disable Windows Firewall itself.
Three operating styles change the workflow. Click to Block lets applications connect until the user blocks them. Ask to Connect prompts when an unfamiliar app attempts access. Block All cuts most network access until the mode changes. Some Windows security traffic remains allowed so that blocking it does not trigger a severe Defender reaction.
Old rules matter
Ask to Connect can surprise a user when Windows Firewall already contains an allow rule created by another program. That earlier rule may let an app reach the network briefly before GlassWire’s decision appears. The installer can reset Windows Firewall when a completely fresh rule set is required, but that action also removes deliberate rules used by other services.
Blocking the wrong system process can interrupt name resolution, updates, or a local network share. GlassWire names the executable and publisher, yet the user still has to determine why it connects. Restoring a rule is easier than diagnosing several unrelated applications after a broad block.
Remote monitoring
GlassWire can display activity from another computer or server that the owner controls. The remote machine must also run GlassWire, remote access starts disabled, and an administrator unlocks it before setting a password. Restricting access to a known static IP reduces exposure.
A server behind a router may need port forwarding before the monitoring computer can reach it. Opening that route without a strong password exposes a management service to the Internet. Remote monitoring reads another GlassWire database; it does not silently discover every device behind that server.
Alerts need context
GlassWire can flag DNS changes, proxy changes, ARP spoofing patterns, new network devices, and suspicious hosts. VirusTotal checking remains off until the user enables it. These signals narrow an investigation, but a changed DNS server can come from an intentional VPN and a VirusTotal result can contain false positives. The file path, signature, connection destination, and timing still decide the next action.






