Windows connection visibility + investigation

See what connected. Understand what it means.

HypNO takes a Windows connection and ties it back to the application, destination, history, and evidence behind it. You can see what changed, troubleshoot a blocked app, or decide whether anything needs to change without jumping between several tools.

Connection worth reviewingWindows endpoint
ApplicationDiscord
Connected toCloudflare network · TCP 443
Why HypNO showed itNew destination for this application
Application checkPublisher and signature verified
IP researchOptional
Next stepReview the connection history before changing access
EvidenceOriginal connection and supporting evidence stay visible while you investigate
01 · What HypNO does

From one connection to a clear decision.

HypNO starts with the connection and breaks down which application made it, where it went, and what changed. From there, you can decide what actually needs your attention.

1. What connected?

See the application and executable behind the connection.

2. Where did it go?

See the destination, port, network, and connection history.

3. What changed?

Spot new destinations or changes in application behavior.

4. What does the evidence say?

Review Windows evidence first, with optional outside context when useful.

5. What should I do?

Monitor, investigate, troubleshoot, allow, block, or make no change.

6. Did it work?

Verify the result and keep a recovery path when something was changed.

02 · Capabilities

See what works now and what is still being built.

The core Windows connection and application evidence already works. The list below shows what is available now and what is still being built around it.

Current foundation

The working evidence layer HypNO is being completed around.

Works now

Live Windows connections

See active and ended TCP/UDP connections tied to the app that created them.

Works now

Application identity

See the process, service, path, publisher, signature, version, hash, and start time.

Works now

Connection history

Compare first-seen, last-seen, active, and ended activity.

Works now

PCAP / PCAPNG investigation

Turn captures into IPs, flows, packets, names, ports, totals, and timing.

Works now

IP and network context

Add Local GeoLite, MaxMind, and AbuseIPDB without mixing the evidence sources.

Works now

Application investigation + recovery

Trace related application evidence and preserve recovery before removal.

Works now

Product workflow

Make the working evidence easier to review, save, and support.

In progress

Saved investigations

Keep evidence, decisions, actions, verification, and recovery together.

In progress

Change-focused alerts

Surface meaningful changes without creating one popup per socket.

In progress

Sanitized reports

Export readable evidence without credentials or unrelated private data.

In progress

Product Health

Show service, provider, update, retention, backup, and coverage state.

In progress

Deeper investigation and response

These remain in development until their own acceptance gates pass.

In development

Firewall baseline + rule audit

Explain where rules came from, what they affect, and what changed.

In development

Smart Interactive

Review meaningful new behavior and create scoped native Windows Firewall decisions.

In development

Strict Interactive

Advanced block-first mode for unknown outbound traffic after its safety gates pass.

In development

Windows Evidence Timeline

Put Windows, network, provider, AV, firewall, and user actions in time order.

In development

Process lineage

Show what launched the app and related parent/child activity.

In development

Antivirus scan handoff

Ask a supported installed antivirus to scan the exact executable.

In development

Enhanced Windows evidence

Add Event Log, ETW, and performance context without depending on them.

In development

Security-suite / firewall coexistence

Detect when another security product or organization policy changes which response is safe to offer.

In development
About

Why I built HypNO.

I built HypNO after using several different tools just to understand one Windows connection. The information was already there, but I wanted the entire investigation to be easier to follow without having to move between several applications to put the story together.

I am not trying to remove the value of specialist tools. I am building the workflow between them.
Tools HypNO connects

Different specialties. One investigation.

Each of these tools is useful for something different. HypNO brings the parts needed for one Windows investigation into the same workflow instead of trying to replace them.

TCPView

Shows active TCP/UDP endpoints and the process or service behind them.

HypNO adds: history, executable identity, IP context, and the next step.

Wireshark

Provides much deeper packet and protocol analysis.

HypNO adds: a simpler PCAP path tied to the wider application investigation.

simplewall

Allows or blocks application traffic through Windows filtering.

HypNO adds: the investigation and evidence before the firewall decision.

Windows Firewall Control

Makes native Windows Firewall rules easier to manage.

HypNO adds: application context, preview, verification, audit, and recovery.

Portmaster

Monitors application connections and controls where apps can connect.

HypNO adds: deeper Windows identity evidence and guided review.

GlassWire

Visualizes network activity, alerts, and application traffic.

HypNO adds: deeper identity evidence and a recovery-aware investigation workflow.

Revo Uninstaller

Uninstalls programs and looks for leftover files, folders, and registry entries.

In developmentHypNO direction: investigate first, preserve recovery, then verify what actually belongs to the application.

Full network-monitoring platforms

HypNO starts deeper on the Windows endpoint.

PRTG, Auvik, Domotz, SolarWinds, and OpManager are broader network-monitoring products. HypNO starts with application-to-connection investigation and expands outward later.

Works now In progress In development
Capability PRTG Auvik Domotz SolarWinds OpManager HypNO
Follow a Windows app to its connection Different focusDifferent focusDifferent focusDifferent focusDifferent focus Works now
Check app file, publisher, signature, version, and hash Different focusDifferent focusDifferent focusDifferent focusDifferent focus Works now
Review packet captures Traffic sensorsTraffic analysisDiagnosticsPacket and flow toolsTraffic analysis Works now
Review IP owner, location, and reputation context Different focusTraffic contextDevice contextTraffic contextDifferent focus Works now
Windows Firewall investigation + scoped rule control Different focusDifferent focusDifferent focusDifferent focusFirewall monitoring Works now
Save investigations and create reports ReportsReports and historyReports and historyReportsReports In progress
Find and identify devices on the local network YesYesYesYesYes In development
Monitor while the Windows PC is off Remote probeCollectorCollectorMonitoring platformProbe or server In development
Device health, SNMP, topology, and multiple locations YesYesYesYesYes In development

Comparison last verified: August 21, 2026.

Comparison claims and provider terms will be checked again before retail launch.

In-app IP research preview

IP research with context.

These examples show why an IP score should not be read by itself. The application, destination, and other evidence still need to make sense before a decision is made.

H
HypNO Beta IP Research · AbuseIPDB example
Selected public IP
1.1.1.1
0% Reported Abuse Score
Lower reported abuse
Research request

chrome.exe selected 1.1.1.1 for an optional AbuseIPDB lookup. The result is shown separately from the Windows evidence.

Reported Abuse Score

Shows how strongly AbuseIPDB reports suggest that this IP has been involved in harmful activity.

Lower reported abuseHigher reported abuse
Supporting evidence only. This score does not prove by itself that the application or connection is safe or harmful.
HypNO explanation

This address belongs to a well-known public DNS service. AbuseIPDB is not flagging it as suspicious right now. It should not be blocked based on this score alone.

Verify at the source

Review AbuseIPDB's current report details separately from the Windows application evidence. Current provider data may differ from this static example.

Selected IP1.1.1.1
H
HypNO Beta IP Research · AbuseIPDB example
Selected public IP
185.199.108.153
50% Reported Abuse Score
Review the context
Research request

chrome.exe selected 185.199.108.153 for research after the destination appeared as new in this example.

Reported Abuse Score

Shows how strongly AbuseIPDB reports suggest that this IP has been involved in harmful activity.

Lower reported abuseHigher reported abuse
Supporting evidence only. This score does not prove by itself that the application or connection is safe or harmful.
HypNO explanation

This address is used by GitHub Pages, where many unrelated websites can share the same network address. AbuseIPDB has reports tied to it, so review the website Chrome opened before deciding whether anything is wrong.

Verify at the source

Review AbuseIPDB's current report details separately from the Windows application evidence. Current provider data may differ from this static example.

Selected IP185.199.108.153
H
HypNO Beta IP Research · AbuseIPDB example
Selected public IP
45.148.10.141
100% Reported Abuse Score
Higher reported abuse
Research request

unknown-helper.exe selected 45.148.10.141 for research after a first-observed connection from an unknown application.

Reported Abuse Score

Shows how strongly AbuseIPDB reports suggest that this IP has been involved in harmful activity.

Lower reported abuseHigher reported abuse
Supporting evidence only. This score does not prove by itself that the application or connection is safe or harmful.
HypNO explanation

This address has a very high reported-abuse score and a large number of recent reports. Because the program is also unknown, this connection should be reviewed right away before it is allowed to continue.

Verify at the source

Review AbuseIPDB's current report details separately from the Windows application evidence. Current provider data may differ from this static example.

Selected IP45.148.10.141

ILLUSTRATIVE EXAMPLE. These are real public IP addresses shown with static provider snapshots from August 20, 2026. The application events are fictional, provider data can change, and this website does not perform a live lookup.

03 · Optional connection research

Add more context when you need it.

HypNO works without online provider accounts. If you connect one, it adds more context to the public IP you choose to research without replacing the Windows evidence.

Adds offline approximate location and network-owner context. Useful because HypNO can add IP context without sending the address to an online provider.

Works now

Adds additional IP location and network information. Useful when you want more context about where a public IP is registered and which network it belongs to.

Works now

Shows whether an IP has been reported for abusive activity. Useful as a reputation signal when deciding whether a connection deserves more investigation.

Works now

Adds broader threat-intelligence research around files, URLs, and other observables. Useful when you want another independent source while investigating something unfamiliar.

In progress

Helps explain whether an IP is part of widespread internet scanning or other commonly observed activity. Useful because an unfamiliar scanner is not automatically targeting only your PC.

In progress

Checks for known malware-related indicators of compromise. Useful when you want to know whether an IP, domain, URL, or file indicator has been associated with known malware activity.

In progress
Local first.

HypNO works without online providers. Connected sources add extra context only when you choose to research a public IP.

04 · Firewall & interactive protection

Understand the firewall before you change it.

HypNO looks at the firewall rules that are already there before suggesting a change. It also checks whether Windows Firewall or another security product may be controlling the connection.

In development

Monitor Only

Read, explain, and baseline the firewall without changing policy.

In development

Strict Interactive · Advanced

Block unknown outbound traffic first, then review the application and decide what to allow.

Firewall baseline

Know what is already there.

Rules are grouped by source and ownership before cleanup is suggested. Questionable local rules follow Review → Disable & Test → Restore or Delete.

Firewall baseline · illustrative Default outbound: Allow
Windows / Protected96 rules
Organization Managed18 rules
Installed Applications61 rules
HypNO Managed4 rules
User / Local20 rules
Needs Review9 rules
Unresolved6 rules
Example counts only. The real application will use the current Windows policy stores and effective rule state on that machine.
Already use a paid security suite?

HypNO should not fight it.

If ESET, Bitdefender, or another product may control traffic, HypNO keeps the investigation available and limits misleading Windows Firewall actions. Vendor-specific rule control requires a separately supported integration.

Network-control state · illustrative In development
Third-party firewallDetected
Example productESET Endpoint Security
HypNO investigationAvailable
Windows Firewall inventoryAvailable
HypNO Windows Firewall responseLimited
Reason: another security product may be enforcing network traffic. HypNO keeps the evidence available without pretending a local Windows rule is the final authority.
01Inventory
02Explain
03Review
04Disable & Test
05Keep / Restore / Delete
Interactive modes stay truthful.

Smart Interactive reviews behavior after Windows may already have allowed the first connection. Strict Interactive is the later block-first mode.

05 · Evidence you can follow

One case. Every important event in order.

HypNO keeps the important parts of an investigation together in the order they happened. You can see what the application did, what each source found, what changed, and whether the response worked.

unknown-helper.exe · investigation timeline Illustrative example · In development
1:14:03 PM
unknown-helper.exe startedFirst-seen executable · process identity captured
WINDOWS
1:14:04 PM
Publisher could not be verifiedExecutable identity remains incomplete
IDENTITY
1:14:05 PM
First connection to a new networkOutbound TCP 443 · new ASN for this application
NETWORK
1:14:07 PM
AbuseIPDB research completedProvider evidence added separately from Windows facts
PROVIDER
1:14:09 PM
Microsoft Defender scan requestedExact investigated executable submitted to the installed AV workflow
DEFENDER
1:14:18 PM
Defender scan completed · No detectionSupporting evidence only — not proof the application is safe
DEFENDER
1:14:30 PM
User reviewed the evidenceDecision moved from investigation to a possible scoped response
USER
1:14:34 PM
Firewall authority checkedWindows Firewall is the supported response path in this illustrative example
SECURITY
1:14:42 PM
Windows Firewall block createdHypNO-owned rule · exact scope previewed before approval
FIREWALL
1:14:47 PM
Reconnection blockedObserved behavior now matches the reviewed response
VERIFY
1:14:48 PM
Response verifiedWindows readback, connection behavior, and recovery state retained in the case
VERIFY
Quietly recorded

Normal activity stays visible without becoming notification spam.

chrome.exe → 127.0.0.1Expected browser/helper behavior
HISTORY
chrome.exe → TCP 443Repeated behavior already established
HISTORY
Known application → known ASNNo meaningful identity or destination change
HISTORY
Notification shown

Interrupt the user when the application story meaningfully changes.

unknown-helper.exe → new ASNFirst-seen executable · publisher unknown · new destination
REVIEW
Firewall rule scope broadenedNew inbound Allow on Public profile
REVIEW
Application reconnects after blockResponse needs verification or escalation
REVIEW
Your antivirus stays independent.

HypNO can ask your antivirus to scan the application and bring that result back into the investigation. It keeps antivirus and firewall decisions separate, so one result does not automatically decide the other.

06 · Who HypNO is for

Built for people who need the story behind the connection.

HypNO is meant to be easy to follow without hiding the technical evidence. It is useful for people learning Windows networking and for people who need to troubleshoot real connections.

IT support & early-career professionals

Move from “the app cannot connect” to application identity, destination, firewall context, and a repeatable investigation.

Students & serious learners

Learn networking from real Windows activity instead of isolated definitions.

Advanced Windows & paid-AV users

Keep your existing protection while adding deeper application and network context.

Independent technicians & small IT teams

Use saved cases, reports, support evidence, and later deployment/multi-machine workflows for repeatable customer work.

07 · Common questions

Know what HypNO is—and what it is not.

These answers cover the main questions about what HypNO does and where it fits. More technical detail is shown where it matters in the application.

Is HypNO antivirus?
No. HypNO investigates Windows network behavior while Defender or another antivirus remains a separate protection layer.
I already pay for antivirus. Why would I use HypNO?
Your antivirus tells you whether it detected a threat. HypNO explains which app connected, where it went, what changed, and what happened after a reviewed response.
What if my security suite has its own firewall?
HypNO should keep the investigation available and show the detected firewall/security state. It should not create a competing Windows rule and claim that it fixed the connection.
Can HypNO help when an application cannot connect?
Yes. The product direction checks the app, destination, Windows Firewall rules, organization policy, and other security layers before deciding what may be blocking it.
Can HypNO block a connection?
Controlled Windows Firewall rule work already exists. Stronger preview, authority checks, verification, recovery, and drift handling are still being built.
What is Smart Interactive?
The planned recommended mode shows meaningful new or changed behavior and lets the user review a scoped Windows Firewall decision. It does not claim to pause the first outbound packet.
What is Strict Interactive?
The planned advanced mode blocks unknown outbound traffic first, then asks for a reviewed decision. It remains In development until its safety testing is complete.
Does HypNO delete firewall rules it does not recognize?
No. It is designed to classify and baseline rules first, then use a recovery-first Disable & Test workflow for questionable local rules.
Do I need online provider accounts?
No. Core Windows analysis and Local GeoLite work without them; connected providers add optional context.
Does “No Record Found” mean an IP is safe?
No. It only means that provider did not return a matching record.
Does HypNO replace Wireshark?
No. Wireshark remains the deeper packet-analysis specialist; HypNO ties packet evidence into the wider Windows investigation.
Can HypNO scan a suspicious application?
The planned scan handoff can ask a supported installed antivirus to scan the exact executable. The result stays separate evidence and is not treated as proof of safety.
Does HypNO use Event Log or performance data?
The planned Evidence Timeline can use relevant Event Log, optional ETW, and selective performance context. Core monitoring remains useful without them.
Will HypNO monitor more than one PC?
Later. The Windows endpoint comes first; network collection, the Sensor, and technician/multi-site workflows follow afterward.
08 · Private beta & what comes next

Finish the Windows experience before expanding it.

I want the first Windows release to feel complete before I expand HypNO into broader network monitoring. That means finishing the investigation workflow, firewall behavior, reports, updates, and Windows 11 testing first.

  • Finish the remaining provider connections, reports, and update flow
  • Finish Smart Interactive and make sure HypNO works cleanly alongside existing security software
  • Finish saved investigations, the Evidence Timeline, quieter alerts, and antivirus scan handoff
  • Finish Product Health, signing, deployment, and final Windows 11 testing
  • Expand into broader network monitoring after the Windows release is solid

Interested in trying HypNO?

Private beta signup is not open yet. This preview shows what I’ll ask for when it is, and nothing here is sent or stored.

This preview does not send or save anything.