See everything. Control everything. Trust nothing.
Compatibility : Cripple is designed to work seamlessly alongside your existing network and security toolsβincluding dnscrypt-proxy, torifier, YogaDNS, NextDNS, AVG and other antivirus & VPN programs. It intelligently detects local proxies and security suites to operate cooperatively without creating network conflicts or infinite DNS loops.
Every second your devices are online, dozens of applications are silently phoning home. Your browser leaks DNS queries through encrypted side channels. Your operating system broadcasts telemetry you never consented to. Smart devices on your network talk to servers in countries you've never heard of. And traditional firewalls? They can't even see most of it.
Cripple strips all of that away.
It's not just a DNS blocker. It intercepts traffic at the raw packet level β before it ever leaves your machine β so nothing escapes. Not hardcoded IPs, not encrypted DNS tunnels, not stealthy IPv6 broadcasts. If something tries to talk to the internet without your permission, Cripple kills it.
- Complete visibility β A live dashboard showing every connection every app on your system is making, right now, in real time.
- Surgical control β Block individual domains, entire apps, or nuke your entire network connection with one click.
- Protection that actually works β Unlike browser extensions or hosts-file blockers, Cripple operates at the OS kernel level. Apps can't bypass it, and neither can your browser's DNS-over-HTTPS.
- Zero-configuration privacy β Ships with 3.2+ Million unique blocked domains out of the box across 49 active threat feeds. Ads, trackers, telemetry, and malware β gone before you even open a browser.
- Hardware stealth β Includes MAC Address Randomization and network adapter hardening to prevent device fingerprinting.
- Native OS Firewall Sync β Automatically detects your manually set Windows Firewall block/allow rules and natively enforces them at the packet level.
- Your network, offline β Run it on a Raspberry Pi, a NUC, or a home server and protect every device on your LAN without installing anything on them.
- How It Works
- What Gets Blocked
- Active Blocklists & Threat Feeds
- Protecting Your LAN
- Android
- Headless & Remote Management
- Safety & Anti-Lockout
- Under the Hood
- Getting Started
- Release Notes
Most "ad blockers" and "firewalls" work at a single layer β they rewrite DNS queries or filter HTTP headers. Cripple is different. It works at three layers simultaneously:
Every DNS query your system makes passes through Cripple first. Known bad domains (ads, trackers, telemetry, malware) get sinkholed β they resolve to 0.0.0.0 so the connection never happens. This is fast, silent, and invisible to the apps making the requests.
Why this matters to you: Your browser loads pages faster because ad networks never even get contacted. Your system uses less bandwidth. And tracking companies get zero data about you.
Some apps don't use DNS. They hardcode IP addresses directly. Cripple hooks into the OS kernel (WinDivert on Windows, NFQueue on Linux, PF on macOS) and inspects every outbound packet before it leaves. If the destination is on a blocklist β or if the connection wasn't explicitly allowed β it gets destroyed.
Why this matters to you: This closes the biggest gap in traditional blockers. When your graphics driver phones home to an analytics server via raw IP, Cripple catches it. Browser extensions never will.
For encrypted traffic, Cripple reads TLS handshake headers (SNI) to identify the destination domain even when the payload is encrypted. It also detects DNS-over-HTTPS tunnels and force-routes them back through the sinkhole.
Why this matters to you: Chrome, Firefox, and Edge all try to bypass your DNS settings using DoH. Cripple intercepts 30+ DoH providers and redirects them. Your privacy settings actually stick.
Out of the box, with no configuration, Cripple blocks:
| Category | What it covers | Why you care |
|---|---|---|
| Ads | Banner ads, video pre-rolls, pop-ups, native ads | Faster page loads, cleaner browsing, less bandwidth |
| Trackers | Cross-site tracking pixels, fingerprinting scripts | Companies can't build a profile of your browsing habits |
| Telemetry | OS phoning home, app crash reports, usage statistics | Your computer stops reporting your behavior to Microsoft/Apple/Google |
| Malware | Known C2 servers, phishing domains, botnets, exploit kits | Protection against drive-by downloads and compromised sites |
| IoT Chatter | Smart devices calling home to cloud servers | Your smart TV stops sending your viewing habits to advertisers |
You can customize everything: add your own blocklists (paste any URL), create per-app rules, set temporary "time bomb" allows that auto-expire, or switch between three protection modes:
| Mode | Behavior | Best for |
|---|---|---|
| π Loose | Blocks confirmed bad domains only | Maximum compatibility, minimal friction |
| π° Normal | Blocks ads + trackers + telemetry | Daily use (recommended) |
| π» Ghost | Blocks all non-essential traffic, sinkholes discovery queries (WPAD, NetBIOS, AD SRV), & hardens adapter bindings | Maximum privacy, zero-leak stealth |
Cripple aggregates 3,236,262+ unique domains from 42 active, high-reputation blocklists and threat intelligence feeds. Feeds are automatically updated on tailored schedules:
| Blocklist Source | Category | Update Interval | Description |
|---|---|---|---|
| URLhaus Malware | Malware / C2 | 1 hour | Real-time malware distribution and C2 server domains |
| Feodo Tracker Botnet C2 | Malware / C2 | 1 hour | Active botnet command and control servers |
| HaGeZi TIF | Threat Intelligence | 2 hours | Threat Intelligence Feeds blocking phishing, malware, and exploits |
| DShield Suspicious Domains | Security | 4 hours | High-risk suspicious domains reported by SANS Internet Storm Center |
| PhishTank / Phishing Army | Malware / Phishing | 4 hours | Verified active phishing campaigns and credential harvesting sites |
| Blocklist Source | Category | Unique Domains | Description |
|---|---|---|---|
| HaGeZi Ultimate | Ads / Trackers | 677,000+ |
Comprehensive high-coverage ad and tracker blocklist |
| HaGeZi Pro Plus | Ads / Trackers | 586,000+ |
Expanded protection covering intrusive popups and trackers |
| OISD Big | Ads / Trackers | 333,000+ |
Curated zero-false-positive ad and telemetry blocklist |
| AdGuard Base Filter | Ads | 158,000+ |
Primary AdGuard desktop & mobile ad-blocking rules |
| Steven Black Unified | Ads / Malware | 93,000+ |
Amalgamated hosts file combining top community blocklists |
| Dan Pollock Hosts | Ads | 12,900+ |
Classic hosts file covering ad networks and malware hosts |
| AdGuard Mobile Ads | Mobile Ads | 10,700+ |
Mobile ad networks, in-app trackers, and SDK analytics |
| AdAway Default | Ads | 6,500+ |
AdAway mobile ad server blocking list |
| Peter Lowe AdServers | Ads | 3,500+ |
Curated list of ad servers and tracking hosts |
| AdGuard Regional Filters | Regional Ads | 30,000+ |
Specific rules for Russian, Japanese, Turkish, Chinese, and French sites |
| EasyList Regional Filters | Regional Ads | 15,000+ |
Specific rules for German, Italian, Dutch, Arabic, and Korean (YousList) sites |
| Blocklist Source | Category | Description |
|---|---|---|
| HaGeZi Windows Telemetry | System Telemetry | Blocks Microsoft Windows 10/11 telemetry and diagnostics |
| HaGeZi Apple Telemetry | System Telemetry | Blocks macOS and iOS analytics and diagnostics endpoints |
| HaGeZi Mobile Telemetry | System Telemetry | Native telemetry blocking for Xiaomi, Huawei, Vivo, Oppo, Realme, & Amazon |
| WindowsSpyBlocker (Spy/Update/Extra) | System Telemetry | Deep Windows telemetry, diagnostics, and forced update server blocking |
| HaGeZi DoH/DoT Providers | Security | Prevents browser Encrypted DNS (DoH/DoT) bypass attempts |
| v2fly Identity Lists | Identity Mapping | Category mapping for Microsoft, Google, Apple, Amazon, Facebook, Cloudflare, & Fastly |
Cripple doesn't just protect one machine β it can protect your entire local network.
When you run Cripple on multiple devices, they communicate via encrypted UDP broadcasts using a shared pre-shared key (PSK). If one device detects a threat, it instantly broadcasts an encrypted LOCKDOWN command β and every other Cripple instance on the network locks down simultaneously.
Setting it up is two commands:
# On your first device β get the auto-generated key
python main.py --get-psk
# On every other device β paste it in
python main.py --set-psk "your-key-here"The PSK uses Fernet (AES-128-CBC) encryption with anti-replay nonces, and the listener is always active β it survives killswitch mode, ghost mode, and interface failures with automatic socket recovery.
Two levels of network isolation, depending on how serious the threat is:
| Ghost Mode | Killswitch | |
|---|---|---|
| Severity | β Stealth isolation | β Total network death |
| Whitelists | Ghost Mode preferences honored | Nothing honored β no exceptions |
| SSH | Survives if whitelisted in Ghost prefs | Disconnects (unless SSH Safeguard is on) |
| Remote recovery | --unghost works remotely |
Requires physical access |
| LAN Shield | Listeners stay active | Everything dies |
| Use case | "Go dark but stay manageable" | "Nuke it β I'll deal with it in person" |
Both require typing YES to confirm in the CLI. Pressing Enter always cancels.
When Ghost Mode is engaged on Windows, Cripple executes advanced system hardening to secure the host natively against reconnaissance and leaks, without relying on suspicious PowerShell droppers:
- Absolute Zero PowerShell: Uses native OS APIs to avoid all Machine Learning heuristic AV flags (
Bearfoos.A!ml). - Native Protocol Disablement: Disables NetBIOS over TCP/IP (NetBT) and File and Printer Sharing (LanmanServer) natively.
- LLTD Mapper & Responder Neutralization: Completely disables
ms_lltdioandms_rspndrdiscovery protocols across all network adapters via Windows Group Policy registry injections. - Fail-Open Restoration: If the PyInstaller payload is unexpectedly closed or crashes, the Watchdog guarantees these stealth registry keys and protocol settings are immediately restored to standard OS defaults.
Cripple runs natively on Android with two VPN modes β choose at launch:
Cripple becomes your device's VPN. All traffic β DNS, TCP, UDP β flows through Cripple's TUN interface. Blocked connections are silently dropped at the packet level. No root required.
When to use this: You want one app that handles everything. No other VPN app needed.
DNS-only filtering at 127.0.0.1:5353. Designed for users who already run a VPN (WireGuard, AdGuard, etc.) and want Cripple to handle just the blocking.
When to use this: You're already running a VPN for geo-unblocking or work, and you want Cripple for privacy filtering alongside it.
Cripple is designed to run silently on servers, Raspberry Pis, NUCs, and embedded systems. Start it with --service and manage everything via SSH.
No daemon needed β these work directly on the database:
python main.py --get-psk # Display LAN Shield PSK
python main.py --set-psk "key" # Import PSK from another device
python main.py --export backup.json # Full profile export
python main.py --import backup.json # Import on another machine
python main.py --set ssh_safeguard true # Never lock yourself outLive commands β sent to the running daemon via IPC:
python main.py --block evil-tracker.com # Block a domain instantly
python main.py --allow example.com # Whitelist a domain
python main.py --mode PARANOID # Escalate protection
python main.py --status # Check daemon status
python main.py --stats # View 24h statistics
python main.py --ghost # Go dark (with confirmation)
python main.py --killswitch # Nuclear option (with confirmation)
python main.py --update-blocklists # Force blocklist refreshFull reference: CLI Guide
Cripple is designed to never lock you out of your own machine, even when running the most aggressive security modes.
A single setting that guarantees you can always SSH in β no matter what:
python main.py --set ssh_safeguard trueWhen enabled, inbound connections on port 22 and 2222 are always allowed β even during killswitch, ghost mode, paranoid mode, or strict inbound blocking. This check runs before every other security evaluation in the engine.
Auto-enabled when you start Cripple in headless mode (
--service). You'll never accidentally lock yourself out of a remote Pi.
Every CLI command that could sever your connection requires explicit confirmation:
| Command | Confirmation required? |
|---|---|
--killswitch |
β
Must type YES (Enter cancels) |
--ghost |
β
Must type YES (Enter cancels) |
--mode PARANOID |
β
Must type YES (Enter cancels) |
--blockinbound |
β
Must type YES (Enter cancels) |
--unkillswitch |
β Instant (recovery should be fast) |
--unghost |
β Instant |
--mode NORMAL |
β Instant |
All prompts can be bypassed with --force for scripted automation.
If Cripple crashes, the watchdog automatically restores:
- DNS settings to their original state
- Firewall rules (removes all NetStrip rules)
- IPv4/IPv6 protocol bindings (re-enables if they were disabled)
- Killswitch state (clears the lockdown flag)
You'll never end up with a bricked network because Cripple died mid-operation.
For the technically curious β here's what powers the engine.
Two independent layers that never block each other:
- Core Engine β Multi-threaded C-level daemon: packet evaluation, SQLite logging, DNS proxying, kernel route monitoring, anomaly detection
- GUI β Hardware-accelerated CustomTkinter visualizer, fully optional. Can be closed for pure headless operation
| Layer | What it does |
|---|---|
| π‘οΈ NIST CSF 2.0 Resilience | Process watchdog with crash recovery, memory-bound caching, IPC timeouts (Slowloris mitigation), and thread exhaust prevention |
| π‘οΈ ISO/IEC 25010 Quality | Architecture meets ISO standards for Reliability, Performance Efficiency, and Security via strict fail-safe state handling and WAL DB |
| π‘οΈ Post-Quantum Cryptography | Pure-Python AES-256-CBC + HMAC-SHA512 + HKDF-SHA512 (immune to Grover's quantum attack & WDAC blocks) |
| π HMAC-SHA512 Watchdog | Ephemeral 512-bit keyed hashes continuously verify integrity of all engine files & modules against live tampering |
| DLL Sideloading Mitigation | LOAD_LIBRARY_SEARCH_DEFAULT_DIRS + dynamic _MEIPASS search path restriction at startup |
| IPC Command Validation | Regex-validated domain commands on the IPC socket |
| Shell Sandboxing | All system commands use shell=False with isolated arguments |
| Anti-Replay Nonces | LAN Shield broadcasts include cryptographic nonces β replaying old packets does nothing |
| Crash Report Guarantee | Essential domains are whitelisted, crash reports retry 5Γ with exponential backoff |
| Anti-Corruption DB | SQLite WAL mode with thread-safe isolation |
| ARP Lockdown | Gateway MAC address pinned β prevents ARP spoofing / MITM attacks |
| eBPF XDP Mode | On Linux, fileless eBPF programs injected into the NIC for wire-speed filtering |
Cripple is engineered to align with two major cybersecurity standards:
- NIST Cybersecurity Framework 2.0 (CSF 2.0): Specifically addressing the Govern, Protect, Detect, and Recover functions. Cripple automatically restores network configurations (DNS, firewall rules, active bindings) on ungraceful exits, monitors process integrity via a cryptographic watchdog, and implements local Denial of Service (DoS) protections.
- ISO/IEC 25010:2011: System quality strictly models the standards for Reliability (fault tolerance, recoverability), Security (confidentiality, integrity), and Performance Efficiency (memory-bound caches, socket timeouts, adaptive thread polling).
| Optimization | Effect |
|---|---|
| Adaptive polling | 250ms refresh when GUI visible, 2000ms when headless |
| View caching | Tab swaps in O(1) via grid_remove(), never destroyed |
| Lazy preloading | Tabs pre-instantiated at 300ms intervals for zero-delay switching |
| Debounced resize | Batched window resize events prevent layout thrashing |
| Flicker-free dashboard | Pre-allocated widget pool with in-place configure() updates |
| 15x scroll speed | Framework-level mouse wheel patching |
Grab the pre-compiled binary from Releases. Run as Administrator/sudo. No Python required.
git clone https://github.com/neohiro/Cripple-NetStrip.git
cd Cripple-NetStrip
pip install -r requirements.txtWindows: python main.py
macOS / Linux: sudo python3 main.py
Headless: sudo python3 main.py --service
Android: Built via GitHub Actions β standalone .apk
- OS: Windows 10/11, macOS, Linux, Android
- Python: 3.10+ (not needed for pre-compiled binaries)
- Permissions: Administrator/Root (Android uses VPN Service)
- System App Block Active Red Button: When
Block System Connectionsis toggled ON, system process rows (svchost.exe,explorer.exe,conhost.exe,System,services.exe, etc.) in the live app connections sidebar immediately show theirBlock Allbutton highlighted in bright red (#f43f5e), clearly indicating an active system process block state. - Real-Time Sidebar Event Sync: Toggling
Block System Connectionsin the Dashboard or Settings tab immediately broadcastsMODE_CHANGEDto instantly update all active process row toggle visuals without requiring a manual UI reload.
- Strict 3-Mode Architecture: Standardized protection levels strictly to
Ghost,Normal, andLooseacross the GUI, tray menu, rules view, and engine. - Dashboard & Settings Layout Alignment: Positioned
Block System ConnectionsandSmart Shieldtoggles prominently above the protection mode selector on the Dashboard tab, allowing fast access to blocklist/whitelist modifier switches.
- Ghost & Paranoid Unified Subsets: Fixed
engine.pyandblocklists.pymode checks soGHOST,PARANOID, andSTRICTshare the exact same high-security mode bucket (mode_scope = "PARANOID"). Selecting Ghost mode now properly loads high-security user rules and engages strict firewall/adapter security defaults. - Normal & Loose Subsets:
NORMAL(Standard) andLOOSEmodes share the standard security subset (mode_scope = "STANDARD"). Switching protection mode buckets seamlessly activates the corresponding user settings and engine defaults.
- Explicit 3-State Neutral Toggle: Introduced explicit
neutraluser state when bothAllow AllandBlock Allare toggled off. Toggling an active bulk button off now turns both buttons transparent (OFF) simultaneously and restores individual connection/domain evaluation. User explicit settings (Allow, Block, or Both Off) take absolute priority over implicit Paranoid or System block defaults. - Mode-Scoped Rule Isolation: Rule modifications and database cache invalidations are isolated by
mode_scope(STANDARDvsGHOST/PARANOID). Switching modes initialises each protection mode's default rules without cross-mode interference. - System Idle & Kernel Origin Resolution: Added origin local port and domain mapping tracking to attribute sockets created under PID 0 (
System Idle Process) or PID 4 (System) back to their parent application (e.g.AntiGravity). Kernel connections for whitelisted apps properly inheritUSER_ALLOWEDstatus, eliminating false positive blocks. - Windows Executable Metadata: Updated embedded
version_info.txt(VSVersionInfoPE metadata) to version3.3.18.0. Identifies company, product, and version for Windows Firewall and UAC prompts. (Note: Windows SmartScreen shows "Publisher: Unknown" for unsigned builds as SmartScreen requires paid EV Authenticode code-signing certificates).
- Instant Log Scroll: Pre-allocates all 50 row widgets at view init, eliminating the first-render 350-widget creation stall that caused initial scroll sluggishness.
- Allow All / Block All 3-State Toggle: Separated implicit block indicators (Paranoid default, system block setting) from the explicit toggle state so the 3-state cycle (
None β Allow β None β Block β None) works cleanly without state reapplication on poll. - Updater Reliability: Reduced initial auto-update delay from 30 min to 2 min, doubled download timeout to 30s, added 2-attempt retry per source, and skipped throttle for never-downloaded sources β ensuring all 43 online feeds are fetched.
- Glitch-Free Connection Logs: Optimized
LogViewrow geometry with fixed height frames (pack_propagate(False)), transparent process container background, right-aligned scrollbar padding for header alignment, and smooth mousewheel event handling to eliminate interlacing, glitching, and line overlapping during scrolling. - Filter Lists Category Counters & Search: Implemented
_get_category_countwith robust category normalization checkingstats,sources_metadata, anddomain_mapacross all threat categories so counts and domain results render accurately on category click or search query.
- Multi-Core Parallel List Parsing & Fast Tokenizer: Parallelized cold filter compilation across all CPU cores with
concurrent.futures.ThreadPoolExecutorand C-speed tokenizing. Bundled pre-indexed binary cache database (NetStrip_cache.pkl) loading 3.25+ million rules in ~2.9s. - Widget-Pool List Virtualization: Replaced UI row destructions with persistent object recycling pools and tuple signature diffing across Rules, Blocklists, Feeds, and Logs.
- Fluid & Responsive UX: Eliminates UI micro-stutters, enables silky-smooth list interactions and instantaneous view navigation.
v3.3.8 β Ghost Mode, Zero-Leak Discovery Sinkholing, Cross-Platform Hardening & Fail-Safe Restoration
- Ghost Mode Overhaul: Rebranded Paranoid Mode fully to Ghost Mode with
#ef4444theme accents, ghost icons, and zero-leak privacy enforcement. - Discovery Sinkholing: Automatic interception of WPAD (
wpad.*), ISATAP, NetBIOS, and Active Directory SRV queries (_ldap._tcp.dc._msdcs.*) withNXDOMAIN/0.0.0.0responses. - Cross-Platform Network Adapter Hardening: Disables privacy-sensitive protocol bindings (LLDP, LLMNR, NetBIOS over TCP/IP, SMB broadcasts, mDNS) on Windows, Linux, and macOS.
- Dual-Layer Restoration: Guaranteed fail-safe restoration of all network settings and bindings on both clean shutdown (
Engine.stop(),atexit,SIGINT/SIGTERM) and abrupt crash recovery via detached watchdog. - Instant Tab Pre-warming: Zero-delay UI tab navigation with background pre-warming.
- Online Filter Feeds Sync: Dynamic custom online blocklist addition and live inverted index synchronization.
- Comprehensive Privacy Audit & Spec Sanitization: Cleaned hardcoded developer paths in
Cripple.specanddns_proxy.py. Replaced with dynamic PyInstaller hook collection (collect_all('customtkinter')). 0 privacy leaks repository-wide. - Boot Freeze Bottleneck Elimination: Shifted blocklist update checks to a 30-minute startup delay and made
NetStrip_cache.jsondisk persistence completely asynchronous. - Filter Lists Infinite Scrolling: Added lazy-loading pagination with page offsets in
blocklists.pyandblocklist_manager.pywith smooth scrolling container. - Full Upstream Blocklist & Threat Intelligence Credits: Attributed all 42 integrated open-source lists across Settings and documentation.
- Settings UI/UX Polish: Responsive description text wrapping and redesigned LAN Shield PSK control card.
- Semantic Versioning Hierarchy Engine: Integrated
parse_version_tupleandis_newer_versionacross update loops to accurately evaluate future release versions (3.3.1<3.3.2<3.10.0). - Connection Log Card Badges & Zero-Thrash: Curved pill badges (
corner_radius=11) with card containers, high contrast, and smooth pooling. - Domain Precedence & Deduplication: Expanded
ESSENTIAL_DOMAINS,SYSTEM_DOMAINS, andUPDATE_DOMAINSand enforced strict category priority over ad/tracker lists. - Filter Lists Tab Nested Scrolling: Smooth scrolling for entire tab combined with dedicated scrollbar for 100-result filter entries.
- LAN Shield Default Active Enforcement: Defaulted LAN Shield to ON across database initialization and GUI sidebar.
- Snappy Window Restore: Filtered root-level
<Map>events and throttledAnimatedLogowhen minimized to eliminate window unminimization latency. - Centralized 4x Smooth Mousewheel Scrolling: Globally monkey-patched
CTkScrollableFramewith 4x scrolling speed and eliminated conflicting local handlers andunbind_allwipes. - LAN Shield Startup Sync: Initialized LAN Shield active mode in engine boot and bound sidebar/view toggles to
lan_shield.is_active. - Connection Logs Row Rendering Fix: Fixed
sqlite3.Rowdictionary indexing to restore full connection log row visibility. - Settings Subtitle Dynamic Text Layout: Added left anchoring and responsive container width wrapping to eliminate text clipping.
-
Post-Quantum Cryptography Engine (
QuantumFernet): Pure-Python AES-256-CBC (14 rounds, 256-bit key) + HMAC-SHA512 for quantum-grade confidentiality and authenticity ($128+$ bits Grover resistance). - RFC 5869 HKDF-SHA512 Key Derivation: Seamlessly elevates existing 44-char keys to 512-bit independent key material, preserving backward pairing while providing full quantum security. Supports native 88-char keys.
- Post-Quantum Watchdog File Verification: Upgraded live file integrity monitoring to 512-bit ephemeral keys and HMAC-SHA512, ensuring instantaneous detection and termination if any engine module is modified or deleted.
-
LAN Shield Post-Quantum Protocol:
NetStrip:PQANOMALY:header with AES-256 broadcast protection. - UI "π‘οΈ QUANTUM-PROOF" Badge: Visual indicator and 512-bit key generator in Settings.
- Pure-Python Fallback: 100% pure-Python symmetric cryptography bypassing WDAC / AppLocker CFFI restrictions.
- Safe DLL Search Path: Safe dynamic DLL loading for PyInstaller frozen binaries.
- LAN Shield ON Default: LAN Shield switch defaults ON on clean boot.
- Centered Action Badges: Full-width logs table with centered
ALLOW/BLOCKbadges. - Smart App Logos & Parent Tracing: Static Cripple logo for internal tasks, native Python icon for standard scripts, and parent icon inheritance for child processes (
jhi_service.exe,NVIDIA Overlay.exe). - Centered DNS Icon: Perfect geometric center alignment for fallback DNS queries.
- Sticky Filter Categories: Category selector cards remain pinned at top for easy category switching.
- Hiccup-Free Settings: Smooth mousewheel canvas scrolling.
- SSH Safeguard β always allows port 22/2222, survives all lockdown modes
- Dual Android VPN β native VPN slot or companion mode alongside another VPN
- 25+ CLI commands β PSK management, settings, export/import, killswitch, ghost, stats
- Confirmation prompts for all lockout-risk commands (killswitch, ghost, paranoid, blockinbound)
- Always-on LAN Shield listener with auto-recovery on socket death
- Crash report delivery guarantee with essential domain whitelist
- HMAC-SHA256 watchdog for engine file integrity
- Adaptive 250ms/2000ms GUI/headless polling
- Anti-replay nonces on LAN Shield broadcasts
- Rebuilt kernel interception engine with zero-leak packet evaluation
- Multi-platform IPC daemon architecture
- Futuristic-minimalist UI theme
- CPU stability improvements
Core Technologies:
CustomTkinter β’ dnslib β’ psutil β’ WinDivert β’ cryptography
Blocklists, Threat Feeds & Identity Lists:
HaGeZi DNS Blocklists β’ AdGuard Filters β’ OISD β’ Steven Black Hosts β’ URLhaus β’ Feodo Tracker β’ PhishTank / Phishing Army β’ DShield / SANS ISC β’ WindowsSpyBlocker β’ v2fly Domain Community β’ Peter Lowe's AdServers β’ Dan Pollock's Hosts β’ AdAway β’ EasyList β’ YousList
MIT License. See LICENSE for details.