Skip to main content
Founding Customer: 50% off year 1 — first 50 customers · code FOUNDING50
Cybersecurity, simplified

See Everything. Detect Threats. Take Control.

Powerful cybersecurity without the complexity.

NetInsightPro brings the essential layers of modern security together in one simple, intelligent platform — without the cost, complexity and steep learning curves of heavyweight security tools.

No card · Runs alongside your antivirus · Windows / Linux / Android · Your data stays on your device

NetInsightProworkstation-001
live
Live Data Flow FlowLens™ · Free
🔔 2 anomalies
chrome
google.com:443TLS↓940K↑42KMETADATA
slack
slack.com:443TLS↓88K↑30KMETADATA
cursor
api.openai.com:443TLS↓22K↑310KPII
ollama
localhost:11434PLAIN↓1.8M↑210KMETADATA
unknown
185.220.101.x:22PLAIN↓12K↑68KSENSITIVE

See where your data and services connect. Detect spyware, suspicious behaviour and AI-driven anomalies — and surface the network activity of malware and trojans your antivirus can't see. Block unwanted destinations with a click — all from one interface.

See Everything

See what's happening across your devices, data and connections.

Detect Threats

Detect threats, anomalies and suspicious activity before they become a problem.

Take Control

Block unwanted services, connections and destinations with a click.

Blocking is per destination host on Windows, Linux and Android, enforced by the OS firewall — not per app, and not yet on macOS.

New · AI-Agent & MCP SecurityNew

See and secure the AI agents & MCP servers on your fleet

AI assistants like Claude Desktop and Cursor now run local tools through MCP (Model Context Protocol) — a fast-growing, mostly invisible endpoint attack surface. NetInsightPro discovers every AI agent and MCP server across your fleet, risk-scores each one with evidence, and lets you block a risky one in a click.

Discovery & inventory

Find every AI agent and MCP server running across your Windows, Linux and Android endpoints.

Risk scoring with evidence

Each one scored Low to Critical, with the evidence and drill-down behind the verdict.

One-click block

Block a risky agent or MCP destination across the fleet in a single click.

Discovery, inventory, risk-scoring and blocking are live today. Vulnerability scanning is included and rolling out.

0.0%Enterprise uptime SLA
0/7On-device monitoring

Supported platforms & integrations

  • Windows 11
  • Windows Server 2022
  • Ubuntu 20.04+
  • Debian 12
  • Fedora 38+
  • Android 7.0+
  • macOS (soon)
  • WFP
  • Netfilter
  • VpnService
  • OCSF
  • SCIM 2.0
  • OIDC
  • .NET
  • Python
  • Node.js
The gap

What existing tools miss

The problem

  • Antivirus asks “is this file bad?” — it doesn't watch where your data goes
  • Firewalls block ports — not the app sitting behind them
  • Wireshark shows packets but can't block
  • Cloud SIEMs only see what you've already shipped off-device
  • Mercenary/Pegasus-class spyware egress hides in normal traffic
  • AI-worm / LLM-exfil traffic slips past signature-based tools

How NetInsightPro closes it

  • The egress layer, alongside your antivirus — never instead of it
  • Per-app attribution at the kernel level — which app opened which connection
  • One-click block of a destination host on Windows, Linux and Android — instant, no reboot
  • Local-first: your network data stays on your device
  • Spyware Shield: desktop egress matched to lab-attributed infra — indicators, not diagnosis (Pro, early access)
  • AI-worm heuristics flag LLM egress + C2 polling (early access)
Documented threats we detect

These aren't hypotheticals.

The AI-era threats NetInsightPro is built to surface are documented in the security literature — demonstrated by researchers and confirmed in the wild. The per-app egress signal is what surfaces them.

AI-augmented malware crossed from theoretical research into confirmed state-sponsored use in 2025. CrowdStrike documented an 89% surge in AI-enabled adversary operations in their 2026 Global Threat Report.[5]

Morris II
March 2024
Lab — no wild deployment confirmed

First demonstrated self-replicating worm targeting GenAI ecosystems. Exploited RAG database poisoning and adversarial prompt embedding to propagate across ChatGPT-4, Gemini Pro, and LLaVA.

PROMPTSTEAL / LAMEHUG
July 2025
Confirmed in-the-wild (APT28)

First confirmed in-the-wild malware that queries a live LLM (Hugging Face, Qwen2.5) during active attacks to generate Windows reconnaissance commands, then exfiltrates documents via SSH to attacker C2.

SesameOp
November 2025
Confirmed in-the-wild

Backdoor using the OpenAI Assistants API as its C2 channel. A .NET DLL polls an attacker-controlled OpenAI account for encrypted commands — traffic is standard HTTPS to api.openai.com, indistinguishable from legitimate developer use by TLS inspection.

Security posture

Built to be audited, not just trusted.

We publish our security posture and run a responsible-disclosure programme. SOC 2 Type II (target 2026) and ISO 27001 (target 2027) audits are in progress; we don't claim certifications we don't yet hold.

Security posture document available under NDA on request.

One platform. Less complexity. More control.

Enterprise-Grade Security. Simplified.

Forget managing multiple products, complicated dashboards and fragmented alerts. NetInsightPro gives individuals, IT teams and enterprises one clear, unified view — powerful enough for enterprise, simple enough for everyone.

AI-era threat detectionEarly Access

First per-app firewall that catches AI-powered worms

AI-augmented malware now queries ChatGPT and Claude during live attacks to generate recon commands and evade detection. NetInsightPro is the first per-app firewall with dedicated detection for LLM-orchestrated threats — at the network layer, without reading your prompts.

  • LLM API egress monitoring — alerts when malware queries ChatGPT/Claude/Gemini from non-browser processes
  • Lateral move detection — flags LLM-orchestrated reconnaissance: internal follow-up connections shortly after LLM contact
  • Swarm detection — escalates when multiple hosts show the same unknown process making LLM API calls (coordinated activity)
  • Your network data stays on your device. Insight is local. Control is yours.

    — NetInsightPro design principle
  • AI threats need AI defense — on every endpoint, not in the cloud.

    — NetInsightPro design principle
  • Compliance is enforced, not promised. Your data stays on your own hardware — with managed regional hosting as an option.

    — NetInsightPro design principle
Pro — Defensive security

Spyware Shield: continuous, fleet-wide detection of connections to mercenary-spyware infrastructure.

NetInsightPro watches every Windows and Linux desktop in your fleet in real time and flags the moment one opens a connection to infrastructure attributed to Pegasus-class spyware — always on, updated nightly, no manual scans. It's powered by the same published indicators that forensic researchers rely on: the STIX2 feeds from Amnesty International Security Lab and Citizen Lab. Where their toolkits check one device after the fact, Spyware Shield turns that world-class intel into live, continuous protection at scale.

A flag is an indicator, not a diagnosis: it means a connection to attributed infrastructure was observed, not that a device is infected. Spyware Shield complements, and does not replace, expert forensic tools such as Amnesty MVT. For forensic confirmation, contact Amnesty Security Lab.

Continuous, fleet-wide detection

Every desktop, monitored in real time — not one device, scanned by hand, after the fact. Spyware Shield checks live network egress across your whole Windows and Linux fleet the moment a connection opens, so a match surfaces immediately rather than in a later forensic sweep.

Nightly-updated threat intel

The indicator set refreshes automatically every night from the published lab feeds, so your fleet is always checked against the latest attributions — world-class research operationalised into always-on protection, with no manual updates.

Tiered, responsible reporting

Findings carry confidence tiers, never a binary infected/clean verdict. Each report cites its source attribution and points you to expert forensic confirmation — Spyware Shield raises the flag and hands off to the right specialists.

Pro tier · Windows & Linux desktop · Indicators only, not a diagnosis

Desktop-first: Windows and Linux egress matching is available now. Mobile destination-level monitoring requires a separate VPN-layer component not yet built, and Spyware Shield does not detect on-device iOS or Android infections — for mobile forensics, use Amnesty MVT.

Platform features

Six capabilities. One lightweight agent.

From raw packet attribution to enterprise SSO — all without sending your flow data to anyone.

Interactive product demo: an animated cursor opens the AI Threats tab of the admin console, selects a high-severity LLM-exfiltration anomaly, and blocks its egress across the fleet. Illustrative data.

Per-app visibility

Every outbound connection tagged to the process that opened it — not just the IP or port. See exactly which app is talking to which server.

Byte-level monitoring

Real-time byte counts, connection timelines, and destination breakdowns per app. Nothing is aggregated away.

Allow / block rules

One-click block of a destination host, enforced by the operating system's own firewall. Rules persist on your device — no reboot, no service restart, no cloud sync required. Available on Windows, Linux and Android (macOS not yet); blocking is per destination host, not per app.

Enterprise

SIEM forwarder (OCSF)

Push structured OCSF events to your SIEM via webhook. Integrate with Splunk, Elastic, or any webhook-capable endpoint.

Hybrid

Hybrid deployment

Keep raw telemetry on your own infrastructure. Cloud sees only Ed25519-signed daily digests. BYO object storage + KMS.

License-only telemetry

The only signal we receive: your licence key + a hardware fingerprint hash. No flow data, no app names, no destinations — ever.

Intelligence layer

Anomaly detection on per-app egress.

Alerts fire when an app's outbound bytes deviate from its 7-day EWMA baseline. Statistical per-app baselining — not a machine-learning black box. Detection thresholds are service defaults today; per-tenant tuning is on the roadmap.

  • Flags the app, new destinations, and excess byte volume
  • Side-by-side baseline vs. spike comparison
  • One-click host block + optional OCSF SIEM forwarding
Dashboard

Real-software proof.

The same dashboard view — web admin for fleet ops, device client for personal control.

Pro
Device
workstation-001 · sarah.mitchell@example.com · macOS 14.5
Healthy · Pro tier
Anomaly detectedCursor — 7.2x bytes-out baseline at 14:23
AppBytesVerdict
DeepSeekcn
+3.1 MB/min
Qwencn
+1.8 MB/min
Mistraleu
+0.7 MB/min
Cohereus
+0.4 MB/min
Slack
+6.4 MB/min
Dropbox
+14.2 MB/h
bytes_out · last 24h
Sample only — not a live control
Enterprise
Tenant
TechProf Ltd
techprof.netinsightpro.com
Healthy · Enterprise Cloud
Seats142 / 250
HostnameLast seenStatus
workstation-0012 min agoactive
mbp-finance-045 min agoactive
devbox-0114 min agoactive
pos-store-1247 min agoidle
0apps monitored
0.0GB out today
0anomalies this week
0data leaks
Installersv1.0.0+57 · via /download
Build 57
Android 7.0+
arm64 · arm32 · x86_64
73.6 MB
Coming soon
macOS
Apple Silicon + Intel

All installers sha256-verified · account required · Download page →

LivePublished 6 Sept 2026
Windows
x64
Current
Version
v1.0.0+57
Size
11.9 MB
Built
Linux
x86_64
Current
Version
v1.0.0+57
Size
11.8 MB
Built
Android
arm64 · arm32 · x86_64
Current
Version
v1.0.0+57
Size
73.6 MB
Built
macOS
Apple Silicon + Intel
Soon
Version
Coming soon
Size
Built
sha256 —

Full SHA-256 manifest at releases.netinsightpro.com/latest.json · Download page

How NetInsightPro works

From endpoint signal to operator alert — one unified pipeline, fully on-host or hybrid.

  1. Data Sources
    Endpoints · Firewall · DNS
  2. Collectors
    On-host · Hybrid · Cloud
  3. Analytics Engine
    Stream · Enrich · Index
  4. Threat Detection
    Anomaly · AI-Worm · Lateral
  5. Dashboards & Alerts
    Per-tenant · SIEM · Pager
Security & compliance

Built for enterprise trust.

Security architecture

  • Ed25519-signed daily digests (Hybrid tier)
  • mTLS between agent and collector
  • RBAC — per-seat role enforcement
  • Immutable audit log
  • On-prem Hybrid deployment (your infra, your keys)
  • BYO KMS — encryption keys never leave your account

Compliance & standards

  • SOC 2 Type II — audit in progress 2026
  • SAML 2.0 / OIDC SSO
  • SCIM 2.0 provisioning
  • UK GDPR · EU GDPR
  • DORA · BSI C5 · NIS2 alignment (Hybrid)

No banned dates. SOC 2 Type II audit in progress — target 2026; security posture document available under NDA on request.

SIEM integration

Sample OCSF event forwarded to your SIEM

Network Activity · Established (class_uid 4001)
{
  "metadata": {
    "version": "1.3.0",
    "product": { "name": "NetInsightPro", "vendor_name": "NetInsightPro Ltd" }
  },
  "class_uid": 4001,
  "category_name": "Network Activity",
  "activity_name": "Established",
  "severity_id": 3,
  "time": 1717862400000,
  "src_endpoint": { "ip": "10.0.4.17", "hostname": "ws-eu-014" },
  "dst_endpoint": { "ip": "104.18.32.7", "hostname": "api.openai.com" },
  "connection_info": { "protocol_name": "tcp", "direction": "outbound" },
  "observables": [{ "name": "ai_threat_subtype", "value": "llm_exfil_suspect" }]
}
FAQ

Frequently asked questions

More questions? Email support or see the Glossary.

How we compare

NetInsightPro vs. the alternatives

These are the egress tools NetInsightPro is measured against; the antivirus and anti-malware rows at the bottom are the file layer, listed for reference rather than as alternatives. Your antivirus asks “is this file bad?”; NetInsightPro asks “where is your data going, and to whom?”, and runs alongside it rather than replacing it. Wireshark shows packets but cannot block. Firewalls block ports but cannot see which app sits behind them. Only NetInsightPro gives you per-app egress visibility across Windows, Linux and Android — plus enterprise SSO.

NetInsightPro vs. alternatives — feature comparison
ProductPer-app granularityAI agent & MCP securityVulnerability scanningWindowsLinuxmacOSAndroidReal-time blockingEnterprise SSOData stays localSpyware-egress detectionAI-worm detection
NetInsightProSoon
Wireshark
Little Snitch
PortMaster
OpenSnitch
Antivirus
Anti-malware tools

Scroll to compare →

Real-time blocking = one-click blocking of a destination host, enforced by the OS firewall on Windows, Linux and Android; blocking is per destination host, not per app, and macOS blocking is not yet available. macOS support is in development (notarisation pending). Enterprise SSO = SAML 2.0 / OIDC built-in. Spyware-egress detection: Pro tier, Windows/Linux desktop — flags connections to infrastructure attributed to mercenary spyware by Amnesty/Citizen Lab (network indicators, not on-device forensics). AI-worm detection: early access. AI-agent & MCP security: Pro tier — cross-platform discovery, inventory and risk-scoring (Low→Critical, with evidence) of AI agents and MCP servers, with one-click block; fleet-wide automatic blocking on Enterprise. Vulnerability scanning: Pro tier — surfaces known CVEs, vulnerable dependencies and malicious packages in the AI agents and MCP servers NetInsightPro inventories, drawn from public advisory data; rolling out. The antivirus / anti-malware rows scan files for malware — a different layer — and do not scan AI-agent or MCP dependencies. Antivirus / anti-malware rows describe category-typical capabilities — specific products vary — and cover a different protection layer (files); see the cards below. NetInsightPro complements them and does not replace them.

Different layers — better together

Your antivirus and NetInsightPro answer two different questions. NetInsightPro runs alongside your antivirus, never instead of it.

The file layer

Antivirus & anti-malware tools

“Is this file bad?”

  • Malware signatures and behavioural file detection
  • Quarantine and removal of what they find
  • Ransomware protection for your documents
  • Deep scans and clean-up of an already-infected machine

Keep them running. NetInsightPro does not scan files, does not quarantine and does not do ransomware protection.

The egress layer

NetInsightPro

“Where is my data going, and to whom?”

  • Per-app attribution — which app opened which connection
  • AI / LLM endpoint detection — when an app talks to a model provider
  • Mercenary-spyware C2 indicators from published research feeds
  • Data-sovereignty visibility — which jurisdiction your traffic leaves for
  • One-click blocking of a destination host on Windows, Linux and Android

The network layer your file scanner was never built to watch.

Blocking is per destination host, enforced by the OS firewall on Windows, Linux and Android — not per app, and not yet available on macOS. Spyware indicators are network signals, not on-device forensics.

Powerful enough for enterprise. Simple enough for everyone.

Start in 60 seconds. Your data never leaves.

Free account, no card. Create one in seconds, download the installer, and see your app traffic in minutes.

No card required · Windows / Linux / Android · Your data stays on your device