Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

77 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Cripple Logo

NetStrip β€” Cripple

See everything. Control everything. Trust nothing.

Python 3.10+ Platform License Build Status

Compatibility : Cripple is designed to work seamlessly alongside your existing network and security toolsβ€”including dnscrypt-proxy, torifier, YogaDNS, NextDNS, AVG and other antivirus & VPN programs. It intelligently detects local proxies and security suites to operate cooperatively without creating network conflicts or infinite DNS loops.


Why Cripple?

Every second your devices are online, dozens of applications are silently phoning home. Your browser leaks DNS queries through encrypted side channels. Your operating system broadcasts telemetry you never consented to. Smart devices on your network talk to servers in countries you've never heard of. And traditional firewalls? They can't even see most of it.

Cripple strips all of that away.

It's not just a DNS blocker. It intercepts traffic at the raw packet level β€” before it ever leaves your machine β€” so nothing escapes. Not hardcoded IPs, not encrypted DNS tunnels, not stealthy IPv6 broadcasts. If something tries to talk to the internet without your permission, Cripple kills it.

What you get

  • Complete visibility β€” A live dashboard showing every connection every app on your system is making, right now, in real time.
  • Surgical control β€” Block individual domains, entire apps, or nuke your entire network connection with one click.
  • Protection that actually works β€” Unlike browser extensions or hosts-file blockers, Cripple operates at the OS kernel level. Apps can't bypass it, and neither can your browser's DNS-over-HTTPS.
  • Zero-configuration privacy β€” Ships with 3.2+ Million unique blocked domains out of the box across 49 active threat feeds. Ads, trackers, telemetry, and malware β€” gone before you even open a browser.
  • Hardware stealth β€” Includes MAC Address Randomization and network adapter hardening to prevent device fingerprinting.
  • Native OS Firewall Sync β€” Automatically detects your manually set Windows Firewall block/allow rules and natively enforces them at the packet level.
  • Your network, offline β€” Run it on a Raspberry Pi, a NUC, or a home server and protect every device on your LAN without installing anything on them.

πŸ“‘ Contents


How It Works

Most "ad blockers" and "firewalls" work at a single layer β€” they rewrite DNS queries or filter HTTP headers. Cripple is different. It works at three layers simultaneously:

Layer 1 β€” DNS Sinkhole

Every DNS query your system makes passes through Cripple first. Known bad domains (ads, trackers, telemetry, malware) get sinkholed β€” they resolve to 0.0.0.0 so the connection never happens. This is fast, silent, and invisible to the apps making the requests.

Why this matters to you: Your browser loads pages faster because ad networks never even get contacted. Your system uses less bandwidth. And tracking companies get zero data about you.

Layer 2 β€” Packet Interception

Some apps don't use DNS. They hardcode IP addresses directly. Cripple hooks into the OS kernel (WinDivert on Windows, NFQueue on Linux, PF on macOS) and inspects every outbound packet before it leaves. If the destination is on a blocklist β€” or if the connection wasn't explicitly allowed β€” it gets destroyed.

Why this matters to you: This closes the biggest gap in traditional blockers. When your graphics driver phones home to an analytics server via raw IP, Cripple catches it. Browser extensions never will.

Layer 3 β€” Deep Packet Inspection

For encrypted traffic, Cripple reads TLS handshake headers (SNI) to identify the destination domain even when the payload is encrypted. It also detects DNS-over-HTTPS tunnels and force-routes them back through the sinkhole.

Why this matters to you: Chrome, Firefox, and Edge all try to bypass your DNS settings using DoH. Cripple intercepts 30+ DoH providers and redirects them. Your privacy settings actually stick.


What Gets Blocked

Out of the box, with no configuration, Cripple blocks:

Category What it covers Why you care
Ads Banner ads, video pre-rolls, pop-ups, native ads Faster page loads, cleaner browsing, less bandwidth
Trackers Cross-site tracking pixels, fingerprinting scripts Companies can't build a profile of your browsing habits
Telemetry OS phoning home, app crash reports, usage statistics Your computer stops reporting your behavior to Microsoft/Apple/Google
Malware Known C2 servers, phishing domains, botnets, exploit kits Protection against drive-by downloads and compromised sites
IoT Chatter Smart devices calling home to cloud servers Your smart TV stops sending your viewing habits to advertisers

You can customize everything: add your own blocklists (paste any URL), create per-app rules, set temporary "time bomb" allows that auto-expire, or switch between three protection modes:

Mode Behavior Best for
πŸ”“ Loose Blocks confirmed bad domains only Maximum compatibility, minimal friction
πŸ”° Normal Blocks ads + trackers + telemetry Daily use (recommended)
πŸ‘» Ghost Blocks all non-essential traffic, sinkholes discovery queries (WPAD, NetBIOS, AD SRV), & hardens adapter bindings Maximum privacy, zero-leak stealth

πŸ›‘ Active Blocklists & Threat Feeds

Cripple aggregates 3,236,262+ unique domains from 42 active, high-reputation blocklists and threat intelligence feeds. Feeds are automatically updated on tailored schedules:

☠ Rapid Threat Intelligence & Malware Feeds (1h–4h Cycle)

Blocklist Source Category Update Interval Description
URLhaus Malware Malware / C2 1 hour Real-time malware distribution and C2 server domains
Feodo Tracker Botnet C2 Malware / C2 1 hour Active botnet command and control servers
HaGeZi TIF Threat Intelligence 2 hours Threat Intelligence Feeds blocking phishing, malware, and exploits
DShield Suspicious Domains Security 4 hours High-risk suspicious domains reported by SANS Internet Storm Center
PhishTank / Phishing Army Malware / Phishing 4 hours Verified active phishing campaigns and credential harvesting sites

🚫 Advertisement & Tracking Blocklists (24h Cycle)

Blocklist Source Category Unique Domains Description
HaGeZi Ultimate Ads / Trackers 677,000+ Comprehensive high-coverage ad and tracker blocklist
HaGeZi Pro Plus Ads / Trackers 586,000+ Expanded protection covering intrusive popups and trackers
OISD Big Ads / Trackers 333,000+ Curated zero-false-positive ad and telemetry blocklist
AdGuard Base Filter Ads 158,000+ Primary AdGuard desktop & mobile ad-blocking rules
Steven Black Unified Ads / Malware 93,000+ Amalgamated hosts file combining top community blocklists
Dan Pollock Hosts Ads 12,900+ Classic hosts file covering ad networks and malware hosts
AdGuard Mobile Ads Mobile Ads 10,700+ Mobile ad networks, in-app trackers, and SDK analytics
AdAway Default Ads 6,500+ AdAway mobile ad server blocking list
Peter Lowe AdServers Ads 3,500+ Curated list of ad servers and tracking hosts
AdGuard Regional Filters Regional Ads 30,000+ Specific rules for Russian, Japanese, Turkish, Chinese, and French sites
EasyList Regional Filters Regional Ads 15,000+ Specific rules for German, Italian, Dutch, Arabic, and Korean (YousList) sites

πŸ“‘ OS Telemetry & Identity Protection (24h Cycle)

Blocklist Source Category Description
HaGeZi Windows Telemetry System Telemetry Blocks Microsoft Windows 10/11 telemetry and diagnostics
HaGeZi Apple Telemetry System Telemetry Blocks macOS and iOS analytics and diagnostics endpoints
HaGeZi Mobile Telemetry System Telemetry Native telemetry blocking for Xiaomi, Huawei, Vivo, Oppo, Realme, & Amazon
WindowsSpyBlocker (Spy/Update/Extra) System Telemetry Deep Windows telemetry, diagnostics, and forced update server blocking
HaGeZi DoH/DoT Providers Security Prevents browser Encrypted DNS (DoH/DoT) bypass attempts
v2fly Identity Lists Identity Mapping Category mapping for Microsoft, Google, Apple, Amazon, Facebook, Cloudflare, & Fastly

πŸ”‘ Protecting Your LAN

Cripple doesn't just protect one machine β€” it can protect your entire local network.

LAN Shield Mesh

When you run Cripple on multiple devices, they communicate via encrypted UDP broadcasts using a shared pre-shared key (PSK). If one device detects a threat, it instantly broadcasts an encrypted LOCKDOWN command β€” and every other Cripple instance on the network locks down simultaneously.

Setting it up is two commands:

# On your first device β€” get the auto-generated key
python main.py --get-psk

# On every other device β€” paste it in
python main.py --set-psk "your-key-here"

The PSK uses Fernet (AES-128-CBC) encryption with anti-replay nonces, and the listener is always active β€” it survives killswitch mode, ghost mode, and interface failures with automatic socket recovery.

Ghost Mode vs. Killswitch

Two levels of network isolation, depending on how serious the threat is:

Ghost Mode Killswitch
Severity ⚠ Stealth isolation ☠ Total network death
Whitelists Ghost Mode preferences honored Nothing honored β€” no exceptions
SSH Survives if whitelisted in Ghost prefs Disconnects (unless SSH Safeguard is on)
Remote recovery --unghost works remotely Requires physical access
LAN Shield Listeners stay active Everything dies
Use case "Go dark but stay manageable" "Nuke it β€” I'll deal with it in person"

Both require typing YES to confirm in the CLI. Pressing Enter always cancels.

Ghost Mode Hardening & Stealth

When Ghost Mode is engaged on Windows, Cripple executes advanced system hardening to secure the host natively against reconnaissance and leaks, without relying on suspicious PowerShell droppers:

  • Absolute Zero PowerShell: Uses native OS APIs to avoid all Machine Learning heuristic AV flags (Bearfoos.A!ml).
  • Native Protocol Disablement: Disables NetBIOS over TCP/IP (NetBT) and File and Printer Sharing (LanmanServer) natively.
  • LLTD Mapper & Responder Neutralization: Completely disables ms_lltdio and ms_rspndr discovery protocols across all network adapters via Windows Group Policy registry injections.
  • Fail-Open Restoration: If the PyInstaller payload is unexpectedly closed or crashes, the Watchdog guarantees these stealth registry keys and protocol settings are immediately restored to standard OS defaults.

πŸ“± Android

Cripple runs natively on Android with two VPN modes β€” choose at launch:

Native VPN (Default)

Cripple becomes your device's VPN. All traffic β€” DNS, TCP, UDP β€” flows through Cripple's TUN interface. Blocked connections are silently dropped at the packet level. No root required.

When to use this: You want one app that handles everything. No other VPN app needed.

Companion Mode

DNS-only filtering at 127.0.0.1:5353. Designed for users who already run a VPN (WireGuard, AdGuard, etc.) and want Cripple to handle just the blocking.

When to use this: You're already running a VPN for geo-unblocking or work, and you want Cripple for privacy filtering alongside it.


πŸ–₯ Headless & Remote Management

Cripple is designed to run silently on servers, Raspberry Pis, NUCs, and embedded systems. Start it with --service and manage everything via SSH.

25+ CLI Commands

No daemon needed β€” these work directly on the database:

python main.py --get-psk              # Display LAN Shield PSK
python main.py --set-psk "key"        # Import PSK from another device
python main.py --export backup.json   # Full profile export
python main.py --import backup.json   # Import on another machine
python main.py --set ssh_safeguard true   # Never lock yourself out

Live commands β€” sent to the running daemon via IPC:

python main.py --block evil-tracker.com   # Block a domain instantly
python main.py --allow example.com        # Whitelist a domain
python main.py --mode PARANOID            # Escalate protection
python main.py --status                   # Check daemon status
python main.py --stats                    # View 24h statistics
python main.py --ghost                    # Go dark (with confirmation)
python main.py --killswitch              # Nuclear option (with confirmation)
python main.py --update-blocklists       # Force blocklist refresh

Full reference: CLI Guide


πŸ›‘ Safety & Anti-Lockout

Cripple is designed to never lock you out of your own machine, even when running the most aggressive security modes.

SSH Safeguard

A single setting that guarantees you can always SSH in β€” no matter what:

python main.py --set ssh_safeguard true

When enabled, inbound connections on port 22 and 2222 are always allowed β€” even during killswitch, ghost mode, paranoid mode, or strict inbound blocking. This check runs before every other security evaluation in the engine.

Auto-enabled when you start Cripple in headless mode (--service). You'll never accidentally lock yourself out of a remote Pi.

Confirmation Prompts

Every CLI command that could sever your connection requires explicit confirmation:

Command Confirmation required?
--killswitch βœ… Must type YES (Enter cancels)
--ghost βœ… Must type YES (Enter cancels)
--mode PARANOID βœ… Must type YES (Enter cancels)
--blockinbound βœ… Must type YES (Enter cancels)
--unkillswitch ❌ Instant (recovery should be fast)
--unghost ❌ Instant
--mode NORMAL ❌ Instant

All prompts can be bypassed with --force for scripted automation.

Crash Recovery

If Cripple crashes, the watchdog automatically restores:

  • DNS settings to their original state
  • Firewall rules (removes all NetStrip rules)
  • IPv4/IPv6 protocol bindings (re-enables if they were disabled)
  • Killswitch state (clears the lockdown flag)

You'll never end up with a bricked network because Cripple died mid-operation.


βš™ Under the Hood

For the technically curious β€” here's what powers the engine.

Architecture

Two independent layers that never block each other:

  1. Core Engine β€” Multi-threaded C-level daemon: packet evaluation, SQLite logging, DNS proxying, kernel route monitoring, anomaly detection
  2. GUI β€” Hardware-accelerated CustomTkinter visualizer, fully optional. Can be closed for pure headless operation

Security Hardening

Layer What it does
πŸ›‘οΈ NIST CSF 2.0 Resilience Process watchdog with crash recovery, memory-bound caching, IPC timeouts (Slowloris mitigation), and thread exhaust prevention
πŸ›‘οΈ ISO/IEC 25010 Quality Architecture meets ISO standards for Reliability, Performance Efficiency, and Security via strict fail-safe state handling and WAL DB
πŸ›‘οΈ Post-Quantum Cryptography Pure-Python AES-256-CBC + HMAC-SHA512 + HKDF-SHA512 (immune to Grover's quantum attack & WDAC blocks)
πŸ” HMAC-SHA512 Watchdog Ephemeral 512-bit keyed hashes continuously verify integrity of all engine files & modules against live tampering
DLL Sideloading Mitigation LOAD_LIBRARY_SEARCH_DEFAULT_DIRS + dynamic _MEIPASS search path restriction at startup
IPC Command Validation Regex-validated domain commands on the IPC socket
Shell Sandboxing All system commands use shell=False with isolated arguments
Anti-Replay Nonces LAN Shield broadcasts include cryptographic nonces β€” replaying old packets does nothing
Crash Report Guarantee Essential domains are whitelisted, crash reports retry 5Γ— with exponential backoff
Anti-Corruption DB SQLite WAL mode with thread-safe isolation
ARP Lockdown Gateway MAC address pinned β€” prevents ARP spoofing / MITM attacks
eBPF XDP Mode On Linux, fileless eBPF programs injected into the NIC for wire-speed filtering

Compliance Standards

Cripple is engineered to align with two major cybersecurity standards:

  • NIST Cybersecurity Framework 2.0 (CSF 2.0): Specifically addressing the Govern, Protect, Detect, and Recover functions. Cripple automatically restores network configurations (DNS, firewall rules, active bindings) on ungraceful exits, monitors process integrity via a cryptographic watchdog, and implements local Denial of Service (DoS) protections.
  • ISO/IEC 25010:2011: System quality strictly models the standards for Reliability (fault tolerance, recoverability), Security (confidentiality, integrity), and Performance Efficiency (memory-bound caches, socket timeouts, adaptive thread polling).

Performance

Optimization Effect
Adaptive polling 250ms refresh when GUI visible, 2000ms when headless
View caching Tab swaps in O(1) via grid_remove(), never destroyed
Lazy preloading Tabs pre-instantiated at 300ms intervals for zero-delay switching
Debounced resize Batched window resize events prevent layout thrashing
Flicker-free dashboard Pre-allocated widget pool with in-place configure() updates
15x scroll speed Framework-level mouse wheel patching

πŸ“– Getting Started

Option 1: Download (Recommended)

Grab the pre-compiled binary from Releases. Run as Administrator/sudo. No Python required.

Option 2: Run from Source

git clone https://github.com/neohiro/Cripple-NetStrip.git
cd Cripple-NetStrip
pip install -r requirements.txt

Windows: python main.py
macOS / Linux: sudo python3 main.py
Headless: sudo python3 main.py --service
Android: Built via GitHub Actions β†’ standalone .apk

Requirements

  • OS: Windows 10/11, macOS, Linux, Android
  • Python: 3.10+ (not needed for pre-compiled binaries)
  • Permissions: Administrator/Root (Android uses VPN Service)

πŸš€ Release Notes

v3.4.6 β€” System Connection Block Visual Indicator & Real-Time App Row Sync

  • System App Block Active Red Button: When Block System Connections is toggled ON, system process rows (svchost.exe, explorer.exe, conhost.exe, System, services.exe, etc.) in the live app connections sidebar immediately show their Block All button highlighted in bright red (#f43f5e), clearly indicating an active system process block state.
  • Real-Time Sidebar Event Sync: Toggling Block System Connections in the Dashboard or Settings tab immediately broadcasts MODE_CHANGED to instantly update all active process row toggle visuals without requiring a manual UI reload.

v3.3.20 β€” Strict 3-Mode Architecture (Ghost / Normal / Loose) & Dashboard Controls

  • Strict 3-Mode Architecture: Standardized protection levels strictly to Ghost, Normal, and Loose across the GUI, tray menu, rules view, and engine.
  • Dashboard & Settings Layout Alignment: Positioned Block System Connections and Smart Shield toggles prominently above the protection mode selector on the Dashboard tab, allowing fast access to blocklist/whitelist modifier switches.

v3.3.19 β€” Unified Ghost & Paranoid Mode Subsets & Engine Security Alignment

  • Ghost & Paranoid Unified Subsets: Fixed engine.py and blocklists.py mode checks so GHOST, PARANOID, and STRICT share the exact same high-security mode bucket (mode_scope = "PARANOID"). Selecting Ghost mode now properly loads high-security user rules and engages strict firewall/adapter security defaults.
  • Normal & Loose Subsets: NORMAL (Standard) and LOOSE modes share the standard security subset (mode_scope = "STANDARD"). Switching protection mode buckets seamlessly activates the corresponding user settings and engine defaults.

v3.3.18 β€” Explicit 3-State Neutral Toggle & System Idle Origin Resolution

  • Explicit 3-State Neutral Toggle: Introduced explicit neutral user state when both Allow All and Block All are toggled off. Toggling an active bulk button off now turns both buttons transparent (OFF) simultaneously and restores individual connection/domain evaluation. User explicit settings (Allow, Block, or Both Off) take absolute priority over implicit Paranoid or System block defaults.
  • Mode-Scoped Rule Isolation: Rule modifications and database cache invalidations are isolated by mode_scope (STANDARD vs GHOST / PARANOID). Switching modes initialises each protection mode's default rules without cross-mode interference.
  • System Idle & Kernel Origin Resolution: Added origin local port and domain mapping tracking to attribute sockets created under PID 0 (System Idle Process) or PID 4 (System) back to their parent application (e.g. AntiGravity). Kernel connections for whitelisted apps properly inherit USER_ALLOWED status, eliminating false positive blocks.
  • Windows Executable Metadata: Updated embedded version_info.txt (VSVersionInfo PE metadata) to version 3.3.18.0. Identifies company, product, and version for Windows Firewall and UAC prompts. (Note: Windows SmartScreen shows "Publisher: Unknown" for unsigned builds as SmartScreen requires paid EV Authenticode code-signing certificates).

v3.3.17 β€” Log Scroll Pre-allocation, Allow/Block All 3-State Fix, Updater Reliability

  • Instant Log Scroll: Pre-allocates all 50 row widgets at view init, eliminating the first-render 350-widget creation stall that caused initial scroll sluggishness.
  • Allow All / Block All 3-State Toggle: Separated implicit block indicators (Paranoid default, system block setting) from the explicit toggle state so the 3-state cycle (None β†’ Allow β†’ None β†’ Block β†’ None) works cleanly without state reapplication on poll.
  • Updater Reliability: Reduced initial auto-update delay from 30 min to 2 min, doubled download timeout to 30s, added 2-attempt retry per source, and skipped throttle for never-downloaded sources β€” ensuring all 43 online feeds are fetched.

v3.3.16 β€” Log View Scroll Optimization & Filter List Domain Search Fix

  • Glitch-Free Connection Logs: Optimized LogView row geometry with fixed height frames (pack_propagate(False)), transparent process container background, right-aligned scrollbar padding for header alignment, and smooth mousewheel event handling to eliminate interlacing, glitching, and line overlapping during scrolling.
  • Filter Lists Category Counters & Search: Implemented _get_category_count with robust category normalization checking stats, sources_metadata, and domain_map across all threat categories so counts and domain results render accurately on category click or search query.

v3.3.9 β€” Multi-Core Parallel Parsing, Widget-Pool List Virtualization & UI Fluency

  • Multi-Core Parallel List Parsing & Fast Tokenizer: Parallelized cold filter compilation across all CPU cores with concurrent.futures.ThreadPoolExecutor and C-speed tokenizing. Bundled pre-indexed binary cache database (NetStrip_cache.pkl) loading 3.25+ million rules in ~2.9s.
  • Widget-Pool List Virtualization: Replaced UI row destructions with persistent object recycling pools and tuple signature diffing across Rules, Blocklists, Feeds, and Logs.
  • Fluid & Responsive UX: Eliminates UI micro-stutters, enables silky-smooth list interactions and instantaneous view navigation.

v3.3.8 β€” Ghost Mode, Zero-Leak Discovery Sinkholing, Cross-Platform Hardening & Fail-Safe Restoration

  • Ghost Mode Overhaul: Rebranded Paranoid Mode fully to Ghost Mode with #ef4444 theme accents, ghost icons, and zero-leak privacy enforcement.
  • Discovery Sinkholing: Automatic interception of WPAD (wpad.*), ISATAP, NetBIOS, and Active Directory SRV queries (_ldap._tcp.dc._msdcs.*) with NXDOMAIN/0.0.0.0 responses.
  • Cross-Platform Network Adapter Hardening: Disables privacy-sensitive protocol bindings (LLDP, LLMNR, NetBIOS over TCP/IP, SMB broadcasts, mDNS) on Windows, Linux, and macOS.
  • Dual-Layer Restoration: Guaranteed fail-safe restoration of all network settings and bindings on both clean shutdown (Engine.stop(), atexit, SIGINT/SIGTERM) and abrupt crash recovery via detached watchdog.
  • Instant Tab Pre-warming: Zero-delay UI tab navigation with background pre-warming.
  • Online Filter Feeds Sync: Dynamic custom online blocklist addition and live inverted index synchronization.

v3.3.3 β€” Privacy Audit, Upstream Credits, Boot Bottleneck Fix & Filter Pagination

  • Comprehensive Privacy Audit & Spec Sanitization: Cleaned hardcoded developer paths in Cripple.spec and dns_proxy.py. Replaced with dynamic PyInstaller hook collection (collect_all('customtkinter')). 0 privacy leaks repository-wide.
  • Boot Freeze Bottleneck Elimination: Shifted blocklist update checks to a 30-minute startup delay and made NetStrip_cache.json disk persistence completely asynchronous.
  • Filter Lists Infinite Scrolling: Added lazy-loading pagination with page offsets in blocklists.py and blocklist_manager.py with smooth scrolling container.
  • Full Upstream Blocklist & Threat Intelligence Credits: Attributed all 42 integrated open-source lists across Settings and documentation.
  • Settings UI/UX Polish: Responsive description text wrapping and redesigned LAN Shield PSK control card.

v3.3.2 β€” Semantic Versioning, Card Badge Polish, Domain Precedence & Nested Filter Scrolling

  • Semantic Versioning Hierarchy Engine: Integrated parse_version_tuple and is_newer_version across update loops to accurately evaluate future release versions (3.3.1 < 3.3.2 < 3.10.0).
  • Connection Log Card Badges & Zero-Thrash: Curved pill badges (corner_radius=11) with card containers, high contrast, and smooth pooling.
  • Domain Precedence & Deduplication: Expanded ESSENTIAL_DOMAINS, SYSTEM_DOMAINS, and UPDATE_DOMAINS and enforced strict category priority over ad/tracker lists.
  • Filter Lists Tab Nested Scrolling: Smooth scrolling for entire tab combined with dedicated scrollbar for 100-result filter entries.
  • LAN Shield Default Active Enforcement: Defaulted LAN Shield to ON across database initialization and GUI sidebar.

v3.3.1 β€” Snappy Window Restore, Centralized 4x Smooth Scroll & UI Hardening

  • Snappy Window Restore: Filtered root-level <Map> events and throttled AnimatedLogo when minimized to eliminate window unminimization latency.
  • Centralized 4x Smooth Mousewheel Scrolling: Globally monkey-patched CTkScrollableFrame with 4x scrolling speed and eliminated conflicting local handlers and unbind_all wipes.
  • LAN Shield Startup Sync: Initialized LAN Shield active mode in engine boot and bound sidebar/view toggles to lan_shield.is_active.
  • Connection Logs Row Rendering Fix: Fixed sqlite3.Row dictionary indexing to restore full connection log row visibility.
  • Settings Subtitle Dynamic Text Layout: Added left anchoring and responsive container width wrapping to eliminate text clipping.

v3.3.0 β€” Post-Quantum Cryptography Architecture & 512-bit Watchdog Verification

  • Post-Quantum Cryptography Engine (QuantumFernet): Pure-Python AES-256-CBC (14 rounds, 256-bit key) + HMAC-SHA512 for quantum-grade confidentiality and authenticity ($128+$ bits Grover resistance).
  • RFC 5869 HKDF-SHA512 Key Derivation: Seamlessly elevates existing 44-char keys to 512-bit independent key material, preserving backward pairing while providing full quantum security. Supports native 88-char keys.
  • Post-Quantum Watchdog File Verification: Upgraded live file integrity monitoring to 512-bit ephemeral keys and HMAC-SHA512, ensuring instantaneous detection and termination if any engine module is modified or deleted.
  • LAN Shield Post-Quantum Protocol: NetStrip:PQANOMALY: header with AES-256 broadcast protection.
  • UI "πŸ›‘οΈ QUANTUM-PROOF" Badge: Visual indicator and 512-bit key generator in Settings.

v3.2.6 β€” Pure-Python Fernet Engine & Windows Application Control Resiliency

  • Pure-Python Fallback: 100% pure-Python symmetric cryptography bypassing WDAC / AppLocker CFFI restrictions.
  • Safe DLL Search Path: Safe dynamic DLL loading for PyInstaller frozen binaries.

v3.2.0 β€” Major Milestone: Fixed LAN Shield, Logs UI, Icons, Filter Categories & Smooth Settings

  • LAN Shield ON Default: LAN Shield switch defaults ON on clean boot.
  • Centered Action Badges: Full-width logs table with centered ALLOW / BLOCK badges.
  • Smart App Logos & Parent Tracing: Static Cripple logo for internal tasks, native Python icon for standard scripts, and parent icon inheritance for child processes (jhi_service.exe, NVIDIA Overlay.exe).
  • Centered DNS Icon: Perfect geometric center alignment for fallback DNS queries.
  • Sticky Filter Categories: Category selector cards remain pinned at top for easy category switching.
  • Hiccup-Free Settings: Smooth mousewheel canvas scrolling.

v3.1.0 β€” Security Hardening & Full CLI

  • SSH Safeguard β€” always allows port 22/2222, survives all lockdown modes
  • Dual Android VPN β€” native VPN slot or companion mode alongside another VPN
  • 25+ CLI commands β€” PSK management, settings, export/import, killswitch, ghost, stats
  • Confirmation prompts for all lockout-risk commands (killswitch, ghost, paranoid, blockinbound)
  • Always-on LAN Shield listener with auto-recovery on socket death
  • Crash report delivery guarantee with essential domain whitelist
  • HMAC-SHA256 watchdog for engine file integrity
  • Adaptive 250ms/2000ms GUI/headless polling
  • Anti-replay nonces on LAN Shield broadcasts

v3.0.0 β€” Zero-Leak Engine

  • Rebuilt kernel interception engine with zero-leak packet evaluation
  • Multi-platform IPC daemon architecture
  • Futuristic-minimalist UI theme
  • CPU stability improvements

πŸ™ Credits

Core Technologies:
CustomTkinter β€’ dnslib β€’ psutil β€’ WinDivert β€’ cryptography

Blocklists, Threat Feeds & Identity Lists:
HaGeZi DNS Blocklists β€’ AdGuard Filters β€’ OISD β€’ Steven Black Hosts β€’ URLhaus β€’ Feodo Tracker β€’ PhishTank / Phishing Army β€’ DShield / SANS ISC β€’ WindowsSpyBlocker β€’ v2fly Domain Community β€’ Peter Lowe's AdServers β€’ Dan Pollock's Hosts β€’ AdAway β€’ EasyList β€’ YousList


πŸ“„ License

MIT License. See LICENSE for details.

About

Next-gen Network Hardening & Debloater / DNS Sinkhole / Firewall / Domain filter

Topics

Resources

Stars

3 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages