Process & Port Analyzer

Changelog

Full release history and version notes for Process & Port Analyzer – Network & Process Monitor.

Version 3.2

Latest 1 September 2026

A responsiveness and correctness release. Searching no longer re-scans the machine on every keystroke, auto-refresh stops stealing your selection and scroll position mid-read, and “Block this connection” now creates a firewall rule that actually blocks anything.

New

  • Searching is instant. Typing in any search box now filters the rows already on screen instead of re-scanning every process, connection or firewall rule on each keystroke. Esc clears the current tab’s search and Ctrl+A selects every row in a list.
  • A “Flagged for Review” card joins the sidebar summary, showing how many processes the risk heuristics have flagged. Click it to jump straight to the Processes tab.
  • Export the capture log. Export CSV (or Ctrl+E) on the Sniffer tab now saves the packet log to a file — the button previously did nothing there.
  • End several processes at once. Selecting multiple rows and choosing End process now ends all of them, after a confirmation that lists exactly what will be ended.
  • The app remembers more of your view — the auto-refresh interval you picked and the column widths you set on every list are restored next time you open it.

Improved

  • Auto-refresh no longer disrupts you. Your selected rows and scroll position survive a refresh, so you can watch a row at a two-second interval without it jumping away. Refreshes pause while a dialog is open, and the suspicious-process scan no longer re-runs on every tick — a noticeable drop in background CPU use.
  • Failed sign-in attempts load in the background, so the window stays responsive while Windows searches the Security log. Times are shown in your local time zone rather than raw UTC, and when the 100-event limit is reached the app says so instead of quietly truncating the list.
  • The packet sniffer checks for Administrator rights up front rather than failing with a socket error once you press Start, and its log can no longer grow without limit while you are scrolled up reading it.
  • Sharper on high-resolution displays. Tab labels, the summary cards, row action icons and process icons now scale with your display instead of being laid out for a fixed resolution.
  • The Sort by dropdown lists every sortable column, and stays in step when you sort by clicking a column header instead of going blank. Actions always apply to the row you clicked, even when several rows are selected.
  • Smoother lists — summary cards highlight on hover with the hand cursor only over a real card, scrolling long lists is lighter, and row-action tooltips wait for you to settle on an icon instead of flickering past.

Fixed

  • “Block this connection” now creates a rule that works. For an outgoing connection it blocks traffic to the remote address and port, rather than a local port number that Windows never reuses.
  • Firewall rules are matched safely. Enabling, disabling or deleting a rule now confirms the rule was created by this app first. Because Windows deletes firewall rules by name, a rule sharing its name with an unrelated Windows rule is reported rather than both being removed.
  • Geo-location no longer floods the lookup service. Each completed lookup was starting another full pass, producing a rapidly growing pile of duplicate requests.
  • Searching by process ID on the Connections tab no longer hides every UDP row, and the Sniffer tab no longer places the first lines of the capture log behind the controls panel.
  • Several memory and handle leaks — dialogs that were never disposed, signature-check buffers, and risk-scan data that kept discarded rows alive for the life of the app.

Version 3.1

7 July 2026

Offline suspicious-process detection, one-click row actions, and remote host names and locations on the Connections tab.

New

  • Suspicious-process detection. A Risk column on the Processes tab flags processes as High or Medium using local, offline heuristics — unsigned binaries, system-name masquerading, running from temporary folders, self-deleted executables, sideloading, suspicious parent/child chains (Office spawning a shell, for instance), command lines that leave nothing on disk, and risky network behaviour. Hover a flag to see exactly why it was raised. Everything is computed on your machine; no data leaves the device.
  • One-click row actions. Rows on the Processes, Listening and Connections tabs show action icons at the end — run an AI audit, block a port or connection, view a process’s modules, or end the process, without opening the right-click menu. Double-click and right-click still work exactly as before.
  • End process (with confirmation), Open file location and Copy path on every process, listener and connection.
  • Remote host names and locations on the Connections tab. Right-click a connection and choose Resolve host name to look up the remote address’s DNS name. Optionally tick Geo-locate (online) to show each remote address’s country and city — off by default, and it asks for confirmation first, since it sends those addresses to an online lookup service.
  • The app remembers your view — the tab you were on, the Processes filters, protocol and state filters, and the column sort are all restored next time. A “Last updated” time in the status bar tells you how fresh the data is.
  • Refreshed app icon and Store artwork from the new product logo, now shown in the title bar and taskbar too.

Improved

  • Accurate sidebar counts on launch. The Listening Ports and Firewall Rules cards show correct totals immediately, instead of reading zero until you opened each tab.
  • No more freezes. Loading firewall rules and generating an AI audit report run in the background, so the window stays responsive on busy machines.
  • A polished About dialog with the app logo, full version and build number, and runtime details.

Fixed

  • Only one window opens. Launching the app while it is already running brings the existing window to the front instead of opening a duplicate.
  • The Failed Logins card now updates right after you load sign-in attempts.

Version 3.0

2026

Changed

  • Rebuilt from the ground up. A native rewrite of the original application with a single, refined light interface, sharper vector iconography, and improved reliability across every tab.

Version 1.1

June 2026

New

  • Refreshed look — crisp vector icons across the toolbar, tab bar, sidebar buttons, and summary cards that stay sharp at any size and recolour automatically with the dark/light theme
  • Shorter, clearer tab names with matching icons: Processes, Listening, Connections, Failed Logins, Sniffer, Firewall

Improved

  • Firewall rules now accept a single port (80), a list (80,443), or a range (8000-8100) for local and remote ports
  • Addresses are validated when building firewall rules — single IPs, subnets (192.168.1.0/24), ranges (192.168.1.1-192.168.1.50), and keywords such as LocalSubnet or DNS are accepted; duplicates are skipped and invalid entries are rejected with a clear message
  • Memory usage is shown more precisely — small processes now display one decimal (e.g. 0.5) and the Memory column sorts by actual size
  • Faster Failed Logins — loading stops once it passes your chosen time window instead of scanning the entire security log
  • Faster connection and listening lists thanks to smarter lookup of process names and paths

Fixed

  • The "Listen" connection-state filter now works (it previously showed no rows)
  • The module list now shows every module — processes with very many loaded modules are no longer cut off
  • The packet sniffer no longer slows down or freezes during long captures; the on-screen log is kept to a manageable size and the capture file is written more efficiently
  • More stable overall — unexpected errors now show a message instead of closing the app, and closing the window during a capture no longer causes a crash

Version 1.0

January 2026

Initial Release

  • Running process viewer — PID, process name, full executable path, and loaded module list
  • Active TCP/UDP connections — PID, protocol, local/remote IP and port, state, process name
  • Listening ports viewer — all TCP/UDP ports in listening state with owning process details
  • Raw packet sniffer using native Winsock APIs — decodes TCP, UDP, ICMP, and IGMP packets
  • Packet filtering by source/destination IP and port
  • Packet hex dump — timestamped entries with full hex and ASCII side-by-side output to dump.log
  • Windows Firewall rule manager — view, create, enable, and disable rules from within the app
  • Block connection from context menu — pre-fills the firewall rule creator with connection details
  • Sortable columns across all list views with correct numeric sorting for ports and PIDs
  • No external dependencies — uses only native Windows APIs (iphlpapi, psapi, Winsock2, Firewall COM)
  • Supports Windows 7, 8, 10, and 11 (32-bit and 64-bit). Administrator privileges required.

Process & Port Analyzer

View Product & Download User Guide

Versions