ELX Firewall
See every connection, decide every one
A network monitor and application firewall for Windows. It shows which program talks to which host, country and port — live and over time — and lets you allow or block each one down to a single domain, wildcard subdomain or port. In ask mode a new connection waits for your answer instead of failing, so the program never decides on its own that the internet is down.
Rules by domain, not by IP
Allow a program to reach api.example.com but not ads.example.com, or every subdomain with *.example.com. HTTPS is matched by the site name inside the connection, so neighbours on the same CDN address are not caught by mistake.
Ask mode that does not break programs
A new connection from an unknown program is held until you answer instead of being refused. The prompt appears within a fraction of a second; after “Allow” the same connection simply goes through.
Ports as well as hosts
Answer for the whole program, for one domain, for a domain with all its subdomains — and for this port only or for all of them. The same host can have port 443 allowed and port 8080 blocked.
Traffic you can read
A live graph with events pinned on it, per-application, per-host and per-country columns, and a world map with arcs to the countries your traffic goes to. Hover an arc or a country to see which programs are behind it.
Who else is on the network
The LAN scanner finds every device on your subnet and tells you what it is: router, phone, smart speaker, printer, Mac, virtual machine — with the model and operating system where the device announces them.
VirusTotal on request
With your own VirusTotal key, every program that uses the network is checked by its SHA-256. Files are never uploaded; a program flagged by antivirus engines is marked in red.
Screenshots
How blocking works
Filtering is done by the Windows Filtering Platform — the same engine Windows Defender Firewall is built on — in a dynamic session: if the service stops for any reason, its filters disappear with it and the network is never left closed by a crashed process.
| Mode | What happens to a program you have not decided on |
|---|---|
| Click to block | Everything is allowed; you block what you do not want |
| Ask to connect | The first connection waits for your answer in a prompt at the corner of the screen |
| Block all | All traffic is blocked except ELX Firewall itself |
- Per program: incoming and outgoing allowed or blocked separately.
- Per domain and port: rules like
*.example.com,443or8000-8100, for one program or for all of them. - Per folder: allow, block or ask for every program in a folder and its subfolders.
- Temporary: a decision that lasts until the program closes and is never saved.
- Incoming in ask mode are closed by default; local connections and programs you allow explicitly stay open.
Traffic monitor
Per-process traffic is taken from Windows' own network event tracing, host names from the DNS client and from the site name in HTTPS connections — which also covers browsers with their own DNS over HTTPS. The history is kept per minute for two days and per hour after that.
- The graph: incoming and outgoing, 5 minutes to a month, with events such as a program's first connection pinned to the time they happened.
- Columns: applications, hosts, traffic type and countries, each with its share.
- The map: arcs from your location to the countries of remote hosts, live connections only or the whole period.
- The log: first network activity, changed or removed programs, hosts file, DNS and proxy settings, ARP spoofing, new network adapters and devices, remote desktop.
Network scan
Devices are found by ARP across your own subnet. The vendor comes from the MAC address; the type, model and operating system from what the devices announce over mDNS, SSDP/UPnP, SNMP and DHCP. You can name a device and set its location; a new device on the network is reported in the log.
At a glance
- Operating system
- Windows 10 (1809) and 11, 64-bit
- Written in
- Go; interface in WebView2 (Wails)
- Filtering
- Windows Filtering Platform, dynamic session
- Traffic accounting
- ETW: Kernel-Network, DNS-Client, Kernel-Process
- Packet inspection
- WinDivert 2.2 — site names, DNS, holding new connections
- Storage
- SQLite in ProgramData
- Languages
- English, Russian