Real-time network connection monitor for Blue Team work. A desktop GUI that shows which processes talk to the network, to which IPs and domains, correlates that information across views, and persists an event timeline as evidence.
It is not an EDR and doesn't try to be. It's an endpoint-hygiene tool: to quickly review a machine, hunt odd connections, pull the thread on a suspicious process, and keep a record of what happened.
Plenty of tools cover parts of this. PC Sentinel brings them into a single screen with a focus on correlation (IP ↔ process ↔ domain) and on producing reusable evidence.
- Active connections (TCP/UDP) with process, PID, user, local and remote IP/port, state, and connection age.
- Listening ports: the machine's local exposure surface, with an alert when a new one appears mid-session (a classic persistence/backdoor indicator).
- Per-process forensic enrichment: command line, parent process, SHA-256 hash of the executable, and Authenticode signature verification on Windows (mutes false positives from signed binaries).
- Heuristic alerts: typical C2/backdoor ports, scripting processes (LOLBins) with outbound connections, unsigned binaries running outside system paths, tunneling/proxy tools (ngrok, chisel, frp, plink, socat…), long-lived external connections (possible beacons), and DNS-over-HTTPS usage.
- IP intelligence (opt-in): reverse DNS, geolocation (ip-api.com), and reputation (AbuseIPDB), with an alert when an IP crosses the abuse threshold.
- VirusTotal hash and domain reputation (opt-in, via API key).
- DNS visibility: which domain each process resolved, via Sysmon (event 22) or the native Windows log. DGA and DoH detection.
- Cross-tab correlation: from a flagged IP you can see which process used it (even after the connection closed) and which domain it resolved; from a connection you jump to its reputation or its DNS queries. Right-click menus on every table.
- Baseline and deviations: capture the machine's "normal" state (ports, external destinations, binaries, domains); a tab clearly shows what's new and what's gone compared to that snapshot, with the option to accept deviations as normal.
- Evidence: persistent event log in JSONL with daily rotation, plus snapshot export to enriched CSV/JSON (timestamp, host, cmdline, hash, signature, IP intel per row).
- SIEM forwarding: syslog (UDP/TCP, RFC 5424) or HTTP webhook (JSON), non-blocking.
- System tray with native notifications when alerts fire (optional).
- 7 UI languages with auto-detection (en, es, fr, de, zh, ru, pt, it). The log and evidence stay in canonical English so they're stable to grep and correlate.
- Reviewing a machine that "feels off": see at a glance which processes reach the internet and where.
- Fast endpoint triage during an incident, with exportable evidence.
- Watching your own workstation (adware, miners, RATs, tunnelers).
- Establishing a baseline after a clean install and spotting drift later.
- Feeding a homelab SIEM with connection events without deploying a heavy agent.
- Not an EDR or antivirus: it doesn't block, quarantine, or perform automated response.
- It doesn't inspect encrypted traffic. DoH resolved by the browser itself is a structural blind spot (the pattern is detected, not the domain).
- Authenticode signature checks, rich DNS visibility, and near-real-time reading are Windows-only; on Linux/macOS it degrades gracefully (heuristics and canonical mode).
- Python 3.10+ (tested on 3.12 / 3.14).
- Required:
psutil,customtkinter. - Optional:
pystray+pillow(tray and notifications),pywin32(near-real-time DNS reading).
pip install psutil customtkinter
pip install pystray pillow # optional: tray + notifications
pip install pywin32 # optional (Windows): near-real-time DNSpython pc_sentinel.pyFor full data (owning user of each process, all system connections, hashes, ability to terminate protected processes), run it as administrator (Windows) or with sudo (Linux/macOS).
To see the domain each process resolved, you need a DNS query source. The simplest is Sysmon with DnsQuery logging:
setup_sysmon.bat :: installs/configures Sysmon with the bundled config
setup_sysmon.bat repair :: clean uninstall and reinstall (if it got half-registered)Alternative without Sysmon (native log, less reliable):
wevtutil sl Microsoft-Windows-DNS-Client/Operational /e:trueIn Settings ⚙ you configure the AbuseIPDB (IP reputation) and VirusTotal (hash/domain reputation) keys. Both are free and optional; without them, the tool still works with geolocation and heuristics.
- Configuration and keys:
~/.pc_sentinel.json - Events and baseline:
~/.pc_sentinel/(events-YYYYMMDD.jsonl,baseline.json)
Keys are stored in plaintext in the config JSON. Don't sync that file or push it to a repository.
python compile_locales.py :: compile translations (.po -> .mo)
build_windows.bat :: builds dist\PCSentinel.exe (portable, with icon)For an installer, compile installer.iss with Inno Setup 6. Details in EMPAQUETADO.md (packaging guide).
The UI uses gettext. To add a language: copy locale/pcsentinel.pot to locale/<lang>/LC_MESSAGES/pcsentinel.po, translate, and run python compile_locales.py. More detail in locale/README.md.
MIT. Use it, modify it, and redistribute it freely.