Overview Intelligence Compare Tech Specs Download v1.0 GitHub Repository ↗
ThreatLens v1.0 · Now Available

Zero cloud.
Zero compromise.
Absolute visibility.

Traditional antivirus operates as an authoritarian black box, demanding blind faith. ThreatLens delivers complete transparency — real-time process lineage, Shannon entropy heuristics, hardware telemetry, and explainable AI. 100% on your machine.

Windows 10 & 11 100% Offline Architecture Zero Telemetry Uplink MIT Open Source 59 / 59 Tests Passing
ThreatLens // Command Center HUD Live WAL Telemetry
ThreatLens Command Center HUD
Dynamic 0–100 Security Score Native Windows PDH GPU RAM & CPU Clocks Pre-Execution File Dropzone
Captured natively on Windows 11 · PySide6 Cyber HUD
Architectural Intelligence

Engineered for the paranoid.
Designed for everyone.

Five first-principles breakthroughs that eliminate the security black box forever.

Cognitive Security

The 5-Point "Why?" Engine.
Plain English certainty.

When an event fires, legacy antivirus flashes a vague pop-up and shuts you out. ThreatLens decodes raw kernel telemetry into structured human thought: What happened, Who launched it, Where on disk, Why it matters, and Recommended action.

1 What Happened? PowerShell executed a hidden Base64 stager to evade static string detection.
2 Who Did It? powershell.exe (PID 8192), spawned by cscript.exe from invoice.vbs.
3 Where On Disk? C:\Users\TargetUser\Downloads\invoice.vbs
4 Why Does It Matter? Encoded execution bypasses perimeter inspection to load in-memory payloads.
5 Recommended Action Terminate process tree. Binary quarantined into XOR Vault.
Sovereign Privacy

What happens on your PC stays on your PC.

Zero cloud infrastructure. No sign-up. No analytics telemetry. Your security data is written strictly to your local SQLite WAL database.

0
Bytes uploaded to external cloud servers
Neural Intelligence

<2MB Neural Core.
0ms Latency.

An embedded natural language classifier parses obfuscated CLI arguments, Base64 stagers, and LOLBins locally on your CPU.

99%+
MITRE ATT&CK classification accuracy
Forensic Math

Shannon Entropy PE Deconstruction.

Ransomware and crypters pack their binaries into mathematical randomness. Shannon math analyzes byte distributions in microseconds.

>7.4
Packed binary entropy threshold detection
Quarantine Vault

Reversible XOR Header Scrambling.

Renders malicious executables mathematically inert by scrambling PE headers. 100% restorable with zero byte loss on false positives.

100%
Reversible quarantine with zero data destruction
Comparison

Engineered for clarity.
Not blind obedience.

See how ThreatLens compares to default OS protections, legacy suites, and enterprise cloud agents.

Capability ⚡ ThreatLens v1.0 Windows Defender Legacy Antivirus Cloud EDR
Data Sovereignty
Zero packets sent off the device
✓ 100% Offline ⚠️ Cloud Telemetry ✕ Cloud File Scanning ✕ Full Event Uplink
5-Point Explainability
Plain English reason for every alert
✓ Neural Grammar ✕ Generic Trojan Name ✕ Vague Modal ⚠️ Cryptic SOC Codes
Process Lineage Trees
Real-time parent-child execution trace
✓ Live Execution Tree ✕ Not Available ✕ Not Available ✓ Enterprise Tier
Shannon Entropy Math
Flags packed malware >7.4 before execution
✓ Real-time Math ✕ Hash Signatures ✕ Signature Files ✓ Cloud ML Heuristics
Hardware Telemetry
CPU, RAM, native Windows PDH GPU, disk, net
✓ Integrated HUD ✕ Task Manager Only ✕ High CPU Overhead ⚠️ Background Agent
Quarantine Recovery
Reversibility with zero file loss
✓ Reversible XOR ⚠️ Auto-Delete ⚠️ Proprietary Container ⚠️ Cloud Quarantine
Pricing & License
Endpoint cost & freedom
✓ 100% Free · MIT ✓ Built into Windows ✕ $59.99/yr Subscription ✕ $180+/endpoint/yr
Specifications

Tech Specs.

Operating System
Windows 10 & Windows 11 (64-bit x64 architecture)
Built purely on native Windows security primitives with zero third-party kernel driver requirements.
Architecture & GUI
PySide6 (Qt 6.7+) Cyber HUD with 0.45s cold-boot time.
Hardware-accelerated rendering with dark-mode glassmorphism and real-time canvas visualization.
Local AI Model
Embedded CyberNLP Semantic Classifier (<2MB model weight).
100% local CPU inference, zero GPU requirements, multi-turn conversational context memory.
Persistence Engine
SQLite 3 with Write-Ahead Logging (WAL Mode).
Dedicated daemon writer thread with PRAGMA synchronous = NORMAL ensuring sub-millisecond writes under high event volume.
Heuristics & Math
Shannon Entropy Math via pefile static byte analysis (>7.4 packed threshold).
Reversible cryptographic XOR transformation for quarantine isolation with zero file destruction.
Hardware Sensors
Native Windows Performance Data Helper (PDH) engine counters for GPU 3D engine utilization.
Integrated CPU clock frequency, core load, RAM GB utilization, storage C: capacity, and active socket monitoring.
Get Started

Ready to see everything?

One standalone installer. No cloud account. No subscriptions. Absolute endpoint visibility from the moment you launch.

Download ThreatLens_Setup.exe (v1.0)
Windows 10 & 11 (64-bit) • 50 MB • Standalone Setup Wizard • 100% Offline