Persistence scanner
22 autostart surfaces, catalog-aware Authenticode verdicts, optional VirusTotal enrichment.
≈ KnockKnock
FREE · OPEN SOURCE · GPL-3.0 · NO TELEMETRY
A free, open-source outbound firewall. Think LuLu or Little Snitch, for Windows. A startup-program scanner that goes deeper than Task Manager or Autoruns. Alerts when an app turns on your camera or microphone. Ransomware detection, DNS visibility and more: eight auditable tools in the spirit of Objective-See.
Windows 10/11 · x64 & Arm64 · no account · no paywall
THE SUITE
Everything observes and reports. Nothing acts on its own. The two exceptions are explicit and opt-in.
22 autostart surfaces, catalog-aware Authenticode verdicts, optional VirusTotal enrichment.
≈ KnockKnock
Per-application block/allow enforced through the Windows Filtering Platform. Audit-only until you arm it.
≈ LuLu
Live tray alert the moment a new startup item appears, plus reconciliation of what changed while WinSight was off.
≈ BlockBlock
Hidden decoy files, rename/delete-burst and entropy-on-write heuristics. Opt-in.
≈ RansomWhere?
Which process turned the webcam or microphone on, current and historical.
≈ OverSight
Live outbound connections and DNS queries, attributed to processes.
≈ Netiquette, DNSMonitor
Authenticode verdicts with catalog fallback, used by every tool.
≈ What's Your Sign?
Unquoted service paths, writable directories and phantom DLL imports, graded by exploitability on this machine.
≈ DHS
Plus write attribution, per-process drill-down and physical-access detection, with no macOS counterpart. Explore every tool →
THREE WAYS TO USE IT
A desktop and tray application in English, French and Spanish. Every check explains what it observes and what an alert means.
17 verbs with --flagged and --json. Exits non-zero when anything is notable, so it drops straight into a scheduled task.
Local stdio only, read-only, for MCP-compatible AI clients. No network listener.
# run every check
winsight all
winsight persistence --flagged --json
# one process: lineage, modules, connections
winsight process 4242
# when this machine woke, and whether anyone was there
winsight presence
SECURITY POSTURE
The only outbound connection is an explicit, user-initiated VirusTotal hash lookup: a hash, never file contents.
The dashboard is an unprivileged IPC client. An unelevated administrator is refused exactly like a standard user.
Nothing is filtered until an elevated operator arms it. There is no command-line path to arming, by design.
If enforcement cannot be verified exactly, WinSight reports Degraded rather than claiming Active.
The service refuses to install from any path an unprivileged principal can write, and re-checks NTFS file identity before use.
Driver-backed interception is deferred rather than half-built: a production driver needs signing and a safety programme.
Per-user install, no administrator rights required, no .NET runtime to install. Verify every download with checksums and build provenance.
Download WinSight