> ## Documentation Index
> Fetch the complete documentation index at: https://devdocs.xbox.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Inspect and modify network traffic with XMAT

> Use XMAT to capture, inspect, analyze, and modify network traffic from XBOX development consoles and Windows PCs.

[XBOX Multiplayer Analysis Tool (XMAT)](https://github.com/microsoft/xbox-multiplayer-analysis-tool/blob/main/README.md) captures, inspects, and modifies network traffic from XBOX development consoles and Windows PCs. Download the [latest XMAT release](https://github.com/microsoft/xbox-multiplayer-analysis-tool/releases).

XMAT can:

* Proxy HTTP and HTTPS traffic.
* Decrypt and display request and response data.
* Filter captured traffic by host, status code, and method.
* Run C# scripts that modify or terminate requests and responses.
* Capture and analyze low-level network traffic from an XBOX development console.
* Analyze live or saved captures for problematic XBOX service calling patterns.

## Requirements

XMAT requires:

* A development PC running Windows 10, version 1809 (build 17763) or later, or Windows 11.
* Administrator permissions on the development PC.
* The [.NET 10 Desktop Runtime and ASP.NET Core Runtime for Windows x64](https://dotnet.microsoft.com/download/dotnet/10.0), or the .NET 10 SDK for Windows x64.
* For console capture, an XBOX development console running recovery 2106 or later.
* GDK Extensions for XBOX for XMAT features that connect to an XBOX development console.

## Install XMAT

1. Download the current ZIP file from [XMAT releases](https://github.com/microsoft/xbox-multiplayer-analysis-tool/releases).
2. Extract the ZIP file to a local folder.
3. Run XMAT as an administrator.
4. When prompted, install and trust the XMAT root certificate. XMAT uses this certificate to decrypt HTTPS traffic.

## Capture web traffic

1. In XMAT, select the **+** tab.
2. Select the device that runs the title:
   * For the default XBOX development console, select **Default XBOX Console**.
   * For another XBOX development console, select **XBOX Console at IP or Hostname**.
   * For a title on the development PC, select **Local PC**.
3. Select **Web Proxy**, and then select **Add Capture**.
4. Start the proxy:
   * For an XBOX development console, select **Enable XBOX Proxy**. The console restarts and begins sending web traffic through XMAT.
   * For a Windows PC, select **Start Capture**.
5. Launch the title and exercise the scenarios that you want to inspect.
6. Select a connection to inspect its request and response headers and body.

Use the **Host**, **Status**, and **Method** filters to isolate relevant traffic. Select **Save Captures** on the **File** menu to save the capture as an XMATCAP file.

> \[!IMPORTANT]
> If an XBOX development console remains configured to use the XMAT proxy when XMAT isn't capturing, XBOX service checks and other network requests can fail. Select **Disable XBOX Proxy** when testing is complete. The console restarts to apply the change.

## Identify partner service hosts

Before simulating a service outage, capture the title's normal traffic:

1. Start an XMAT web proxy capture.
2. Launch the title and exercise every feature that uses an online service, including:
   * Menus and leaderboards.
   * Multiplayer session creation and joining.
   * Friends and social features.
   * In-title stores.
   * Limited-time events.
3. Use the **Host** filter to review every host that the title contacts.
4. Compare the captured hosts with the title's service inventory and identify the partner-hosted services to test.

Don't block Microsoft, XBOX, or PlayFab service hosts when testing partner service connectivity. Confirm ownership of each host instead of relying only on a substring in its name.

## Block a partner service

XMAT scripts can terminate requests to selected hosts while leaving other traffic available.

1. Open the **Script Editor** in the active web proxy capture.

2. Select the **SSL Connection Request** event.

3. Replace the sample host with each partner service host that you want to block. For example:

   ```csharp theme={null}
   string host = Params.Request.Host.ToLowerInvariant();

   if (host == "api.publisher.example" ||
       host.EndsWith(".api.publisher.example"))
   {
       Params.Continue = false;
   }
   ```

4. Select **Enable**. Verify that the script compiles successfully.

5. Exercise the affected title feature and verify that requests to the selected hosts fail while Microsoft, XBOX, and PlayFab services remain available.

The **SSL Connection Request** event blocks HTTPS connections. If the partner service uses unencrypted HTTP, apply the same host condition to the **Web Request** event and set `Params.Continue` to `false`.

To simulate a service that is unavailable before the title starts, enable the blocking script before launching the title.

> \[!CAUTION]
> XMAT scripts affect live traffic from the selected device. Limit a blocking script to the specific partner hosts required for the test, and disable the script when the test is complete.

## Stop capturing

1. Disable any active scripts.
2. Select **Stop Capture**.
3. If an XBOX development console is using the proxy, select **Disable XBOX Proxy** and wait for the console to restart.

For known issues and support options, see the [XMAT project documentation](https://github.com/microsoft/xbox-multiplayer-analysis-tool/blob/main/README.md#known-issues) and [XMAT support policy](https://github.com/microsoft/xbox-multiplayer-analysis-tool/blob/main/SUPPORT.md).


## Related topics

- [Debugging custom HTTP stacks](/build/console-features/networking/web-requests/debugging-custom-http-stacks.md)
- [XR-074 Loss of Connectivity to XBOX and Partner Services](/publishing/certification/xr/xr-074.md)
- [Development tools for XBOX services](/tools/tools-services/live-tools.md)
- [Capturing network traffic on XBOX One Dev Kits](/build/console-features/networking/tools/netcap-networking.md)
- [Tools for XBOX services](/tools/tools-services/live-tools-nav.md)
