ELX-Software

Networking and remote access

ELX Firewall

See every connection, decide every one

A network monitor and application firewall for Windows. It shows which program talks to which host, country and port — live and over time — and lets you allow or block each one down to a single domain, wildcard subdomain or port. In ask mode a new connection waits for your answer instead of failing, so the program never decides on its own that the internet is down.

v1.0.0.8 Windows Free

Rules by domain, not by IP

Allow a program to reach api.example.com but not ads.example.com, or every subdomain with *.example.com. HTTPS is matched by the site name inside the connection, so neighbours on the same CDN address are not caught by mistake.

Ask mode that does not break programs

A new connection from an unknown program is held until you answer instead of being refused. The prompt appears within a fraction of a second; after “Allow” the same connection simply goes through.

Ports as well as hosts

Answer for the whole program, for one domain, for a domain with all its subdomains — and for this port only or for all of them. The same host can have port 443 allowed and port 8080 blocked.

Traffic you can read

A live graph with events pinned on it, per-application, per-host and per-country columns, and a world map with arcs to the countries your traffic goes to. Hover an arc or a country to see which programs are behind it.

Who else is on the network

The LAN scanner finds every device on your subnet and tells you what it is: router, phone, smart speaker, printer, Mac, virtual machine — with the model and operating system where the device announces them.

VirusTotal on request

With your own VirusTotal key, every program that uses the network is checked by its SHA-256. Files are never uploaded; a program flagged by antivirus engines is marked in red.

Screenshots

Traffic graph with events pinned to the time line
Firewall: incoming and outgoing for every program, hosts and live traffic
An expanded program: domains with ports, live connections and per-host decisions
Ask mode: prompts for new connections, scope and port choice
World map: arcs to the countries your traffic goes to, with a tooltip
Network scan: device type, model, operating system, IP and MAC
Log analysis: first network activity of each program
Settings: security monitors and their notifications

How blocking works

Filtering is done by the Windows Filtering Platform — the same engine Windows Defender Firewall is built on — in a dynamic session: if the service stops for any reason, its filters disappear with it and the network is never left closed by a crashed process.

ModeWhat happens to a program you have not decided on
Click to blockEverything is allowed; you block what you do not want
Ask to connectThe first connection waits for your answer in a prompt at the corner of the screen
Block allAll traffic is blocked except ELX Firewall itself
  • Per program: incoming and outgoing allowed or blocked separately.
  • Per domain and port: rules like *.example.com, 443 or 8000-8100, for one program or for all of them.
  • Per folder: allow, block or ask for every program in a folder and its subfolders.
  • Temporary: a decision that lasts until the program closes and is never saved.
  • Incoming in ask mode are closed by default; local connections and programs you allow explicitly stay open.

Traffic monitor

Per-process traffic is taken from Windows' own network event tracing, host names from the DNS client and from the site name in HTTPS connections — which also covers browsers with their own DNS over HTTPS. The history is kept per minute for two days and per hour after that.

  • The graph: incoming and outgoing, 5 minutes to a month, with events such as a program's first connection pinned to the time they happened.
  • Columns: applications, hosts, traffic type and countries, each with its share.
  • The map: arcs from your location to the countries of remote hosts, live connections only or the whole period.
  • The log: first network activity, changed or removed programs, hosts file, DNS and proxy settings, ARP spoofing, new network adapters and devices, remote desktop.

Network scan

Devices are found by ARP across your own subnet. The vendor comes from the MAC address; the type, model and operating system from what the devices announce over mDNS, SSDP/UPnP, SNMP and DHCP. You can name a device and set its location; a new device on the network is reported in the log.

At a glance

Operating system
Windows 10 (1809) and 11, 64-bit
Written in
Go; interface in WebView2 (Wails)
Filtering
Windows Filtering Platform, dynamic session
Traffic accounting
ETW: Kernel-Network, DNS-Client, Kernel-Process
Packet inspection
WinDivert 2.2 — site names, DNS, holding new connections
Storage
SQLite in ProgramData
Languages
English, Russian

ELX Firewall

See every connection, decide every one

Download

Nearby programs