Installs to user profile
%LOCALAPPDATA%\NetGlobe\, no admin required. No kernel driver, no NDIS hook, no Windows service. Uninstall is a single click.
Real-time network intelligence for Windows. Every outbound TCP and UDP socket is geolocated, attributed to its process, and analyzed locally with 0 telemetry transmissions. Privacy by architecture. Runs entirely on your machine.
NetGlobe unifies what used to be a stack of disconnected tools, netstat, traceroute, WHOIS, mtr, threat feeds, and speed tests, into a single Windows interface. No browser tabs. No copy-pasting IPs. No alt-tabbing.
Real-time enumeration of every outbound TCP and UDP socket, geolocated against a bundled local GeoIP database, no cloud lookups. Arcs are colored by encryption state to make unencrypted traffic visible at a glance, with hop-by-hop RTT and per-region averages on demand.
Every connection checked against FireHOL Level 1/2, Spamhaus DROP/EDROP, Tor exits, and ThreatFox IoCs. BGP and outage signals from IODA and IHR for the wider picture. Every feed URL is auditable, swappable, or replaceable with your own, none are mandatory.
Visualize global traffic paths, monitor latency in real time, and run the network engineer's toolkit, ping, traceroute, MTR with continuous refresh, hop-by-hop loss/latency, path MTU discovery, and DNS lookups, without opening a terminal. Cloudflare-backed speed tests and optional iperf3 integration round out the suite.
Click any connection for WHOIS/RDAP, TLS certificate details (issuer, validity, SANs, ciphersuite), reverse DNS, and a trust score for the process that opened the socket, flagging unsigned binaries, svchost launches, and unusual install locations. One panel, no alt-tabbing.
NetGlobe is a single binary that installs under your user profile with no admin prompt, no kernel driver, no NDIS hook. The GeoIP database is bundled and queried locally. No account creation, no cloud sync, no analytics beacons. Every outbound call is opt-in and listed in Settings.
%LOCALAPPDATA%\NetGlobe\, no admin required. No kernel driver, no NDIS hook, no Windows service. Uninstall is a single click.
One executable, GeoIP bundled, no background daemon. Smaller than most browser tabs, with the entire feature surface inside it.
The local API binds to loopback exclusively. Never exposed to the LAN, never reachable from outside the machine. Auditable in netstat.
Every threat feed URL is listed in Settings, swappable for your own, and fully optional. Disable any feed, replace any feed, or run without any of them.
Available now on the Microsoft Store for Windows 10 and Windows 11. macOS (Apple Silicon + Intel) coming soon to the Mac App Store. Runs entirely on your device.
One ~40 MB binary. No admin prompt. No kernel driver. No telemetry. Install in seconds from the Microsoft Store and start mapping your network the moment it opens.
Our team is here to help with installation, configuration, and product questions. Same engineers who built the app answer the email.