I'm looking for a method to identify the particular process that attempted a connection which ip protection blocked. While it is comforting to see the list of blocked access attempts, there is no information that can be used to isolate the source. I have TCPView running, but since I only get the occasional block (maybe once a day) and tcpview doesn't have a logging facility I haven't been able to correlate a block to a process. Any suggestions? I'd love it if mbam logged the process in the ip block log, but I'm assuming there is a good reason why they didn't do that in the first place. Thanks!