FREE · OPEN SOURCE · GPL-3.0 · NO TELEMETRY

See and control what is actually happening on your Windows machine.

A free, open-source outbound firewall. Think LuLu or Little Snitch, for Windows. A startup-program scanner that goes deeper than Task Manager or Autoruns. Alerts when an app turns on your camera or microphone. Ransomware detection, DNS visibility and more: eight auditable tools in the spirit of Objective-See.

Windows 10/11 · x64 & Arm64 · no account · no paywall

THE SUITE

Eight tools. One roof.

Everything observes and reports. Nothing acts on its own. The two exceptions are explicit and opt-in.

Persistence scanner

22 autostart surfaces, catalog-aware Authenticode verdicts, optional VirusTotal enrichment.

KnockKnock

Outbound firewall

Per-application block/allow enforced through the Windows Filtering Platform. Audit-only until you arm it.

LuLu

Guardian

Live tray alert the moment a new startup item appears, plus reconciliation of what changed while WinSight was off.

BlockBlock

Ransomware detection

Hidden decoy files, rename/delete-burst and entropy-on-write heuristics. Opt-in.

RansomWhere?

Camera & mic monitor

Which process turned the webcam or microphone on, current and historical.

OverSight

Connections & DNS

Live outbound connections and DNS queries, attributed to processes.

Netiquette, DNSMonitor

Hijack scan

Unquoted service paths, writable directories and phantom DLL imports, graded by exploitability on this machine.

DHS

Plus write attribution, per-process drill-down and physical-access detection, with no macOS counterpart. Explore every tool →

THREE WAYS TO USE IT

Dashboard, command line, or your AI client.

Dashboard

A desktop and tray application in English, French and Spanish. Every check explains what it observes and what an alert means.

Command line

17 verbs with --flagged and --json. Exits non-zero when anything is notable, so it drops straight into a scheduled task.

MCP server

Local stdio only, read-only, for MCP-compatible AI clients. No network listener.

# run every check

winsight all

winsight persistence --flagged --json

# one process: lineage, modules, connections

winsight process 4242

# when this machine woke, and whether anyone was there

winsight presence

SECURITY POSTURE

A security tool that never overstates its own protection.

No telemetry, no account

The only outbound connection is an explicit, user-initiated VirusTotal hash lookup: a hash, never file contents.

Authenticated privileged boundary

The dashboard is an unprivileged IPC client. An unelevated administrator is refused exactly like a standard user.

Opt-in enforcement

Nothing is filtered until an elevated operator arms it. There is no command-line path to arming, by design.

Honest state reporting

If enforcement cannot be verified exactly, WinSight reports Degraded rather than claiming Active.

Path-trust hardened

The service refuses to install from any path an unprivileged principal can write, and re-checks NTFS file identity before use.

No kernel driver

Driver-backed interception is deferred rather than half-built: a production driver needs signing and a safety programme.

Know your machine.

Per-user install, no administrator rights required, no .NET runtime to install. Verify every download with checksums and build provenance.

Download WinSight