Windows Network Security & Monitoring Features

CustosXI is a free, local-first network security and monitoring tool for Windows. It provides visibility into network traffic, DNS queries, connections, IP addresses, firewall activity and security signals, with tools to investigate and control unwanted or suspicious network communication.

Light vs Full protection

Choose how deep you want to go on day one. You can switch later in Settings → General.

Light protection is ideal when Npcap is not installed yet. Full protection (Enterprise Capture) unlocks live packet analysis, GEO, Live Traffic, and packet-only settings pages.

Capability Light Full
Npcap requiredNoYes
DNS sinkholeYesYes
Windows Firewall integrationYesYes
Aggression presets & signals (DNS-related)YesYes
Top Risk, timeline, blocks, decisionsYesYes
Live packet captureNoYes
Live Traffic & GEO navigationHiddenYes
AI / Anomaly, Suricata, TLS fingerprint pagesOverlay (“needs Npcap”)Yes
Dashboard traffic chart & packet KPIsHiddenYes
Dashboard DNS block chart & LIGHT badgeYesN/A (Full layout)
Window titleLight ProtectionEnterprise Capture

If you install Npcap later, switch to Full in Settings. CustosXI restarts capture automatically. Guide: Npcap · Getting started.

Core capabilities

Core Windows network security and monitoring capabilities available in Light or Full mode unless noted.

DNS

DNS sinkhole

Intercept DNS queries on the monitored adapter and block unwanted domains before they connect. Reduce ads, trackers, and risky destinations. Optional aggressive mode resolves real IPs and applies temporary firewall blocks with escalating duration.

SIG

Signals & Top Risk

Configurable detection signals score entities over time. Top Risk highlights what matters now; timeline and decision views show why CustosXI alerted or blocked.

PRE

Aggression presets

Built-in postures from Relaxed (alert-focused) to Paranoid. Tune per-signal block tiers and detection parameters without editing raw config files.

FW

Firewall integration

Correlate and manage Windows Firewall rules CustosXI creates. Emergency unblock removes CustosXI block rules when you need a clean network state.

BL

Public blacklists

Import and refresh community threat feeds (IPs and CIDR ranges). Matching runs locally - you choose which feeds to enable.

LOC

Local-first analysis

Traffic context, scores, and logs stay on your machine by default. No hidden upload pipeline for everyday telemetry.

Advanced Network Monitoring & Security Features

Advanced capabilities for deeper network monitoring, traffic analysis and security investigation. Some require Npcap, separate installs, or explicit configuration.

NET

Live traffic & capture

Real-time flows, ports, protocols, and deep packet context. Requires Npcap and Full protection mode.

AI

Local AI anomaly detection

On-device Isolation Forest and statistical baselines flag unusual volume or behaviour. No cloud LLM. Tune in Settings → AI / Anomaly.

IDS

Suricata integration

Optional IDS/IPS you install yourself. CustosXI reads eve.json alerts and correlates them in the dashboard. See Suricata guide.

GEO

GEO, ASN & reputation add-ons

GeoLite2, ASN databases, AbuseIPDB, and other feeds are optional add-ons configured in Settings - not bundled in the installer.

DB

Database & retention

SQLite by default; optional PostgreSQL for larger deployments. Retention and maintenance controls in Settings. Database guide.

UPD

Software updates

Check downloads.custosxi.com for newer builds. Notifications in Settings, About page, and title bar. Release notes on /releases/.

What CustosXI is not

CustosXI is a local-first Windows network security and monitoring tool for individuals and small labs. It complements - but does not replace - antivirus, enterprise SIEM, or professional incident response. See About and Terms.