Privacy-first visibility
Understand which apps and domains communicate from your PC. Analysis runs locally - your traffic is not uploaded to our servers by default.
CustosXI helps you understand what happens on your Windows PC network - and take back control. See traffic, DNS, firewall events, and risk signals locally, block noisy domains that harm privacy, blocks domains and IP addresses known to be malicious or dangerous, analyzes and detects malicious traffic through fully configurable signals and reduce risk and wasted data usage.
CustosXI is built for people who want visibility without giving up control of their network telemetry.
Understand which apps and domains communicate from your PC. Analysis runs locally - your traffic is not uploaded to our servers by default.
See DNS queries in context and block domains that are useless, invasive, or risky - before they turn into full connections.
On-device Isolation Forest and statistical baselines flag unusual traffic - no cloud LLM, no external model API. Tune it in Settings → AI / Anomaly.
Import and refresh community threat feeds (IPs and CIDR ranges). Match traffic against known-bad sources locally - you choose which feeds to enable in Settings.
When the sinkhole blocks a domain, CustosXI resolves its real IPs via upstream DNS and applies temporary Windows Firewall blocks on those addresses. Block duration escalates if the same IP keeps appearing within a configurable window. Requires sinkhole on - Settings → DNS.
Cut trackers, ads, telemetry, and low-value background calls. Useful on metered links, mobile hotspots, and everyday Windows use.
Want the full story behind the project? Read about CustosXI.
CustosXI is freeware: no paywall, no hidden premium tier, and donations are optional. Optional add-ons (GeoIP, Suricata, reputation APIs, and more) are under your control in Settings → Add-on.
Screenshots from the Windows app: traffic, risk signals, firewall, entities, and more - all analyzed locally on your PC.
Click any screenshot to view it full size.
CustosXI does not replace antivirus, firewalls, or enterprise SIEM. It is a local tool to observe, understand, and investigate Windows network behavior. Public beta: many areas are still being improved.
View communications, hosts, ports, external IPs, and signals useful for local analysis.
Read DNS queries, remote destinations, and context about what your system talks to.
Correlate external IPs and autonomous networks to highlight interesting or suspicious traffic.
Bring firewall events into a clearer view linked to the rest of your telemetry.
Display Suricata EVE JSON alerts in a local Windows dashboard.
Focused on local analysis and transparency about components, privileges, and requirements.
CustosXI is free freeware. Privacy, terms, security disclosure, and third-party notices are published openly.
Website vs app - local-first, no automatic upload of traffic to our servers.
Beta software, acceptable use, no warranty, not a full security suite.
Freeware - free personal/lab use; no redistribution without permission.
Safe downloads and security@custosxi.com for reports.
Open-source libraries and optional add-ons - thank you to all contributors.
Project owner, Italy, official contacts.
Official Windows installer. Bundles CustosXI, .NET 10, and required runtimes. Many features are still maturing - see About for AI and beta scope. Npcap, Suricata, PostgreSQL, and GeoLite2 are not included - install or configure separately.
SHA-256 hash and detailed changelog will be published with upcoming releases. Credits: Third-party notices.
Verified builds published on downloads.custosxi.com with file details from R2.
Latest direct link: /download/windows/latest