NetworkTuna provides Windows users with a tool for detecting suspicious network activity and investigating connections around their PC. It records incoming connection attempts, monitors router changes, and lets users review blocked activity and control application network access. The program maintains a long-term traffic history and displays real-time connections, helping users understand which applications use their network. It works alongside existing Windows firewall protection, adding detection and investigation capabilities. Available as a public beta for Windows 10 and 11 on x64 and ARM64, with a 14-day trial and a one-time purchase.
The software focuses on evidence-based network monitoring, showing the details behind each security finding rather than only issuing alerts. Users can inspect blocked connections, follow application traffic, and decide which programs may connect. Router monitoring checks for changes to management access and security keys. Network history remains on the local PC. The program is designed as an addition to Microsoft Defender Firewall or another Windows firewall, providing detection and control features without replacing existing protection. A one-time purchase continues use after the trial period.
NetworkTuna addresses the need for visibility into network activity on Windows systems. It detects port scans and repeated connection attempts from nearby devices, logs incoming attempts, and presents the evidence behind each finding. Optional router checks watch for changes to SSH access and security keys. Users can review blocked activity, control which applications connect, and examine long-term traffic statistics. The program shows real-time connections and identifies installed network-capable applications. It runs on Windows 10 and 11 for x64 and ARM64, available as a public beta with a 14-day trial and a one-time purchase. No subscription is required.
| Port scan and repeated access attempt examination | Evidence-backed findings for reviewed suspicious events |
| Optional router management and SSH key alteration monitoring | Alerts on reopened SSH access or changed keys |
| Logging of incoming reach attempts including firewall-silenced ones | Record of otherwise invisible external contacts |
| Inspection of connections blocked by firewall or application | Overviews and details of silently prevented access |
| Per-application permission, blocking and time-limited access | Notification prompts when apps request network access |
| Longitudinal per-application traffic volume tracking | Historical record of destination and connection patterns |
| Live view of active connections and current bandwidth usage | Recently terminated connections remain inspectable |
| Inventory of network-capable applications and publishers | Allow, block, or ask status overview per program |
| Dashboard summarizing protection checks and recent activity | Light and dark display modes for overview screen |
| Supporting evidence attached to each raised security alert | Assessment material beyond bare notification text |
| Supplemental layer alongside Microsoft Defender Firewall | Adds detection and investigation without replacing firewall |
| Network history retained exclusively on local machine | No transmission of recorded data to external servers |