Current foundation
The working evidence layer HypNO is being completed around.
Works now
Live Windows connections
See active and ended TCP/UDP connections tied to the app that created them.
Works now
Application identity
See the process, service, path, publisher, signature, version, hash, and start time.
Works now
Connection history
Compare first-seen, last-seen, active, and ended activity.
Works now
PCAP / PCAPNG investigation
Turn captures into IPs, flows, packets, names, ports, totals, and timing.
Works now
IP and network context
Add Local GeoLite, MaxMind, and AbuseIPDB without mixing the evidence sources.
Works now
Application investigation + recovery
Trace related application evidence and preserve recovery before removal.
Works now
Product workflow
Make the working evidence easier to review, save, and support.
In progress
Saved investigations
Keep evidence, decisions, actions, verification, and recovery together.
In progress
Change-focused alerts
Surface meaningful changes without creating one popup per socket.
In progress
Sanitized reports
Export readable evidence without credentials or unrelated private data.
In progress
Product Health
Show service, provider, update, retention, backup, and coverage state.
In progress
Deeper investigation and response
These remain in development until their own acceptance gates pass.
In development
Firewall baseline + rule audit
Explain where rules came from, what they affect, and what changed.
In development
Smart Interactive
Review meaningful new behavior and create scoped native Windows Firewall decisions.
In development
Strict Interactive
Advanced block-first mode for unknown outbound traffic after its safety gates pass.
In development
Windows Evidence Timeline
Put Windows, network, provider, AV, firewall, and user actions in time order.
In development
Process lineage
Show what launched the app and related parent/child activity.
In development
Antivirus scan handoff
Ask a supported installed antivirus to scan the exact executable.
In development
Enhanced Windows evidence
Add Event Log, ETW, and performance context without depending on them.
In development
Security-suite / firewall coexistence
Detect when another security product or organization policy changes which response is safe to offer.
In development