macOS Network Traffic Monitor for Per-App Bandwidth

See which apps are using your network, how much bandwidth they consume, where connections go, and which requests deserve a local app firewall rule.

Download iNTM

iNTM traffic view showing per-app macOS network activity
iNTM traffic view showing per-app macOS network activity

What is a Mac network monitor?

A Mac network monitor shows which applications are using the network, how much data each one moves, and which remote endpoints they reach. iNTM does that on the Mac itself: live per-app bandwidth, connection details such as domain, IP address, port, and protocol, plus traffic history you can check later. Menu bar speed and a firewall rule are separate jobs. Use this page when you need the application and the destination, not only a rate or a block.

  • See which Mac app is using the network right now
  • Read per-app upload and download, not only a system total
  • Inspect the domain, IP address, port, and protocol
  • Keep history so a one-time spike is not confused with a daily pattern

What a Mac network monitor is for

Activity Monitor can show that the Mac is busy on the network. A Mac network monitor answers the next questions: which app, which destination, and whether this happened before. iNTM keeps those answers on device, then lets you open a firewall rule only after the connection is identified.

Real-time traffic speed

See upload and download change as connections open and close. The status bar can show the rate while you work; this page is about tying that rate to an application.

Per-app bandwidth usage

Group live traffic by application so a system-wide spike becomes one process. Compare apps instead of guessing from a single total.

Traffic history review

Look back by app and by day, week, or month. A backup that runs every night looks different from a transfer that happened once.

Local app firewall control

When a connection should not continue, create a local rule for the app, domain, IP address, or port. The monitor shows what happened; the rule is the separate control step.

From traffic spike to clear action

A Mac network monitor should turn a vague spike into an application, a destination, and a history you can compare.

  1. Compare apps in Traffic Monitor

    Open iNTM Traffic Monitor, choose a time range, and compare the application chart. Select an app with unexpected traffic to open its connection panel.

  2. Read the connection behind that app

    Check the remote domain, IP address, port, protocol, and when the connection started.

  3. Compare it with earlier days

    Use traffic history to see whether this app does the same thing every day or only did it once.

  4. Leave control to a separate decision

    If the connection should stop, follow the blocking guide and create a local rule. Identification and blocking stay different steps.

Example: investigate an upload while idle

Suppose the menu bar shows sustained upload while you are not sharing a file. In Traffic Monitor, compare app chart items for that period and open the one with unexpected usage.

  • Check the selected app's remote address, port, protocol, and sent bytes before assuming the transfer is unwanted.
  • Compare another time range: a scheduled backup or cloud sync can explain repeated uploads.
  • Only if the destination is unwanted, open the firewall workflow and create a targeted local rule; then check that required sync still works.

Why not just use Activity Monitor?

Activity Monitor is useful for a quick system snapshot. iNTM is designed for people who need ongoing network traffic monitoring, per-app investigation, and connection control.

  • Live speed: Basic network throughput at system level. / Real-time traffic monitoring with app-focused context and status bar visibility.
  • Per-app analysis: Limited detail for investigating app bandwidth patterns. / Per-app usage, historical trends, and connection details in one workflow.
  • Connection control: Observation only. / Local firewall rules for apps, domains, IPs, and ports.
  • Privacy posture: Local system utility. / Traffic metadata and firewall rules are processed locally; packet content is not uploaded.

Private by design

Network monitoring is sensitive. iNTM is built around local processing so you can inspect traffic without turning your Mac activity into a cloud dashboard.

  • No account is required for core network monitoring.
  • Traffic statistics and connection metadata stay in the local app sandbox.
  • Firewall rules execute locally on your Mac.
  • Packet payloads, passwords, and visited content are not uploaded.

macOS network traffic monitor FAQ

What is a Mac network monitor?

It shows which applications are using the network, how much data they transfer, and which remote endpoints they reach. iNTM adds connection details and traffic history on your Mac.

Can iNTM show network traffic by app?

Yes. iNTM groups live and historical traffic by application, so a spike can be traced to a specific Mac app.

How is this different from a menu bar speed display?

A menu bar display shows the current upload and download rate. A Mac network monitor names the app and the destination. Use the speed guide when you only need the rate.

Can I block unwanted network traffic after I find it?

Yes, as a separate step. After the app and endpoint are clear, iNTM can apply a local rule for that app, domain, IP address, or port.

Does iNTM upload packet content?

No. Traffic statistics, connection metadata, and firewall rules are processed locally. Packet payloads, passwords, and visited content are not uploaded.

Speed and blocking are different questions

This page identifies the app and the destination. Use the other two pages when you only need a rate, or when you are ready to stop a connection.

Live upload and download

Keep the current rate in the menu bar when you do not yet need the application name.

Mac Network Speed Monitor

Stop a connection you have identified

Create a local rule only after this monitor has shown the app and the endpoint.

Block Internet Access on Mac

Start monitoring Mac network traffic with context

Use iNTM to turn raw network activity into app-level insight, history, and local control.

Download iNTM for macOS