About CustosXI
A personal project built to give Windows users local-first visibility into network traffic, DNS activity, connections, firewall events, and security signals.
Why this project exists
CustosXI started as a practical answer to a simple question: who is my PC talking to, and why? Over time, that question grew into a broader interest in digital hygiene - less noise, fewer hidden connections, and more control for the person sitting in front of the screen.
The project comes from a long-standing passion for technology: learning how systems work, testing ideas, breaking things safely, and building tools that are useful in real life - not just impressive on paper.
That idea became CustosXI: a free, local-first Windows network security and monitoring tool designed to help individuals and small teams understand everyday network behavior and investigate activity that deserves attention.
CustosXI focuses on the space between simply being connected and actually understanding what a Windows PC is doing on the network. It brings together network traffic visibility, DNS activity, connection context, Windows Firewall events, threat intelligence, and local security signals in one application.
Explore the Windows network security and monitoring features or read the CustosXI documentation to see how the different components work together.
Security and privacy, by design
Security and privacy are not marketing labels here. They are the reason CustosXI exists. The app is built to help you see network activity clearly, reduce unwanted exposure, and make better decisions with local evidence.
- Local-first analysis - network and security context is processed locally on your machine.
- DNS visibility - understand which domains are queried before connections are made.
- Network traffic visibility - inspect connections and traffic patterns to understand what is communicating with your Windows PC.
- Practical blocking - reduce trackers, ads, telemetry, and low-value domains that waste bandwidth and weaken privacy.
- Transparent operation - no hidden cloud pipeline for your network telemetry.
For more information about local processing, external components, downloads, and the security model, see the CustosXI security and privacy page.
Less wasted data, more control
Many apps and websites generate background traffic you never asked for: analytics endpoints, ad networks, redundant sync calls, and domains with little user value. That traffic costs data, battery, and attention - and it can also create unnecessary privacy exposure.
CustosXI helps you identify those patterns and act on them, including through DNS-level controls, so you can cut network noise, save mobile and metered data, and keep your Windows PC closer to what you actually use.
The goal is not to block everything. It is to provide enough network visibility and security context to make informed decisions about what should be allowed, investigated, or blocked.
What CustosXI is (and is not)
CustosXI is a local network security and monitoring tool for Windows: visibility, investigation, analysis, and practical security signals. It is freeware, developed independently in Italy, and shared openly with documentation and security contacts.
The application can bring together network traffic, DNS queries, connection information, IP and ASN context, reputation signals, Windows Firewall events, and local anomaly detection to help build a clearer picture of network activity.
CustosXI does not replace a full antivirus suite, enterprise SIEM, EDR platform, or professional incident response. Instead, it gives individuals and small teams a practical window into everyday network behavior directly on Windows.
AI and anomaly detection (local, no cloud)
CustosXI uses machine learning inside the application code, not a remote AI service. Traffic is analyzed on your PC by a custom Isolation Forest implementation combined with statistical baselines such as Z-score, EWMA, per-IP and optional per-subnet profiles.
- Where it runs: the Worker processes live packets; the AI / Anomaly dashboard and Settings page show metrics, scores, and feedback controls.
- What it does: learns normal traffic patterns over time, flags unusual volume or behavior, and feeds anomaly scores into the threat decision engine alongside DNS, TLS, and reputation signals.
-
What it does not do:
send your traffic to external LLM APIs, train models in the cloud,
or require an OpenAI-style subscription. All model state stays
local in
ProgramData\CustosXI. - Your control: enable or tune detection in Settings → AI / Anomaly; submit false-positive or true-positive feedback from Live Traffic and block explain views.
This area is still maturing in beta - thresholds, calibration, and UI may change between releases. Technical details and current behavior are documented in the CustosXI documentation.
Built with curiosity, improved in public beta
CustosXI is still evolving. Many features - integrations, AI tuning, Suricata workflows, database tooling, and UI polish - are actively being improved. Expect rough edges, incomplete flows, and behavior that may change from release to release.
Beta feedback from real users shapes priorities. If you try it and find bugs, confusing UX, unexpected network behavior, or missing documentation, your reports help determine what gets improved next.
The project is intentionally developed with a focus on practical Windows network visibility rather than making claims of complete protection. The objective is simple: give users more evidence, more context, and more control over their own network activity.
Project owner: Giorgio Ciranni · Italy · Legal information
Custos