Features

What CustosXI does on your Windows PC - locally, without a cloud telemetry pipeline.

Light vs Full protection

Choose how deep you want to go on day one. You can switch later in Settings → General.

Light protection is ideal when Npcap is not installed yet. Full protection (Enterprise Capture) unlocks live packet analysis, GEO, Live Traffic, and packet-only settings pages.

Capability Light Full
Npcap requiredNoYes
DNS sinkholeYesYes
Windows Firewall integrationYesYes
Aggression presets & signals (DNS-related)YesYes
Top Risk, timeline, blocks, decisionsYesYes
Live packet captureNoYes
Live Traffic & GEO navigationHiddenYes
AI / Anomaly, Suricata, TLS fingerprint pagesOverlay (“needs Npcap”)Yes
Dashboard traffic chart & packet KPIsHiddenYes
Dashboard DNS block chart & LIGHT badgeYesN/A (Full layout)
Window titleLight ProtectionEnterprise Capture

If you install Npcap later, switch to Full in Settings. CustosXI restarts capture automatically. Guide: Npcap · Getting started.

Core capabilities

Available in Light or Full unless noted.

DNS

DNS sinkhole

Intercept DNS queries on the monitored adapter and block unwanted domains before they connect. Reduce ads, trackers, and risky destinations. Optional aggressive mode resolves real IPs and applies temporary firewall blocks with escalating duration.

SIG

Signals & Top Risk

Configurable detection signals score entities over time. Top Risk highlights what matters now; timeline and decision views show why CustosXI alerted or blocked.

PRE

Aggression presets

Built-in postures from Relaxed (alert-focused) to Paranoid. Tune per-signal block tiers and detection parameters without editing raw config files.

FW

Firewall integration

Correlate and manage Windows Firewall rules CustosXI creates. Emergency unblock removes CustosXI block rules when you need a clean network state.

BL

Public blacklists

Import and refresh community threat feeds (IPs and CIDR ranges). Matching runs locally - you choose which feeds to enable.

LOC

Local-first analysis

Traffic context, scores, and logs stay on your machine by default. No hidden upload pipeline for everyday telemetry.

Full-mode & optional features

Require Npcap, separate installs, or explicit configuration.

NET

Live traffic & capture

Real-time flows, ports, protocols, and deep packet context. Requires Npcap and Full protection mode.

AI

Local AI anomaly detection

On-device Isolation Forest and statistical baselines flag unusual volume or behaviour. No cloud LLM. Tune in Settings → AI / Anomaly.

IDS

Suricata integration

Optional IDS/IPS you install yourself. CustosXI reads eve.json alerts and correlates them in the dashboard. See Suricata guide.

GEO

GEO, ASN & reputation add-ons

GeoLite2, ASN databases, AbuseIPDB, and other feeds are optional add-ons configured in Settings - not bundled in the installer.

DB

Database & retention

SQLite by default; optional PostgreSQL for larger deployments. Retention and maintenance controls in Settings. Database guide.

UPD

Software updates

Check downloads.custosxi.com for newer builds. Notifications in Settings, About page, and title bar. Release notes on /releases/.

What CustosXI is not

CustosXI is a local network security monitor for individuals and small labs. It complements - but does not replace - antivirus, enterprise SIEM, or professional incident response. See About and Terms.