Version 3.2
Latest 1 September 2026A responsiveness and correctness release. Searching no longer re-scans the machine on every keystroke, auto-refresh stops stealing your selection and scroll position mid-read, and “Block this connection” now creates a firewall rule that actually blocks anything.
New
- Searching is instant. Typing in any search box now filters the rows already on screen instead of re-scanning every process, connection or firewall rule on each keystroke. Esc clears the current tab’s search and Ctrl+A selects every row in a list.
- A “Flagged for Review” card joins the sidebar summary, showing how many processes the risk heuristics have flagged. Click it to jump straight to the Processes tab.
- Export the capture log. Export CSV (or Ctrl+E) on the Sniffer tab now saves the packet log to a file — the button previously did nothing there.
- End several processes at once. Selecting multiple rows and choosing End process now ends all of them, after a confirmation that lists exactly what will be ended.
- The app remembers more of your view — the auto-refresh interval you picked and the column widths you set on every list are restored next time you open it.
Improved
- Auto-refresh no longer disrupts you. Your selected rows and scroll position survive a refresh, so you can watch a row at a two-second interval without it jumping away. Refreshes pause while a dialog is open, and the suspicious-process scan no longer re-runs on every tick — a noticeable drop in background CPU use.
- Failed sign-in attempts load in the background, so the window stays responsive while Windows searches the Security log. Times are shown in your local time zone rather than raw UTC, and when the 100-event limit is reached the app says so instead of quietly truncating the list.
- The packet sniffer checks for Administrator rights up front rather than failing with a socket error once you press Start, and its log can no longer grow without limit while you are scrolled up reading it.
- Sharper on high-resolution displays. Tab labels, the summary cards, row action icons and process icons now scale with your display instead of being laid out for a fixed resolution.
- The Sort by dropdown lists every sortable column, and stays in step when you sort by clicking a column header instead of going blank. Actions always apply to the row you clicked, even when several rows are selected.
- Smoother lists — summary cards highlight on hover with the hand cursor only over a real card, scrolling long lists is lighter, and row-action tooltips wait for you to settle on an icon instead of flickering past.
Fixed
- “Block this connection” now creates a rule that works. For an outgoing connection it blocks traffic to the remote address and port, rather than a local port number that Windows never reuses.
- Firewall rules are matched safely. Enabling, disabling or deleting a rule now confirms the rule was created by this app first. Because Windows deletes firewall rules by name, a rule sharing its name with an unrelated Windows rule is reported rather than both being removed.
- Geo-location no longer floods the lookup service. Each completed lookup was starting another full pass, producing a rapidly growing pile of duplicate requests.
- Searching by process ID on the Connections tab no longer hides every UDP row, and the Sniffer tab no longer places the first lines of the capture log behind the controls panel.
- Several memory and handle leaks — dialogs that were never disposed, signature-check buffers, and risk-scan data that kept discarded rows alive for the life of the app.