
Description
The firewall built into Windows is capable enough; the problem is the Advanced Security console. Stopping one program from phoning home means creating an outbound rule by hand — program path, profile, action — seven or eight clicks deep. Windows Firewall Control inverts that: once it is running, any program attempting an outbound connection raises a tray notification naming the process, the destination address and port and the signature, and clicking Allow or Block writes the rule for you.
It does not replace the Windows firewall, it wraps a usable shell around it, so filtering still happens in the kernel with no extra driver or network shim. Four filtering levels switch instantly: high blocks everything, medium allows only outbound traffic that has a rule, low blocks only what a rule forbids, and no filtering is effectively off. It used to be paid software from Binisoft; after Malwarebytes acquired it, it became free. This is the portable build — unpack and run.
Connection prompts: an outbound attempt raises a popup listing the process, its path, the destination address and port and the signing authority, so you allow, block, or defer the decision on the spot.
Four filtering levels: high, medium, low and off swap with one click, which makes cutting a machine off or opening it up a momentary action.
Rule management: a rules list far easier to work than the system console, with rules by program, address, port or protocol, plus temporary rules that expire on their own.
Invalid rule cleanup: orphaned rules pointing at programs that no longer exist are detected and flagged, so install-and-uninstall churn does not leave a mess behind.
Settings lock: the configuration can be locked against changes by other programs or other people, and it runs fine under a standard user account.
It does not replace the Windows firewall, it wraps a usable shell around it, so filtering still happens in the kernel with no extra driver or network shim. Four filtering levels switch instantly: high blocks everything, medium allows only outbound traffic that has a rule, low blocks only what a rule forbids, and no filtering is effectively off. It used to be paid software from Binisoft; after Malwarebytes acquired it, it became free. This is the portable build — unpack and run.
Features
Connection prompts: an outbound attempt raises a popup listing the process, its path, the destination address and port and the signing authority, so you allow, block, or defer the decision on the spot.
Four filtering levels: high, medium, low and off swap with one click, which makes cutting a machine off or opening it up a momentary action.
Rule management: a rules list far easier to work than the system console, with rules by program, address, port or protocol, plus temporary rules that expire on their own.
Invalid rule cleanup: orphaned rules pointing at programs that no longer exist are detected and flagged, so install-and-uninstall churn does not leave a mess behind.
Settings lock: the configuration can be locked against changes by other programs or other people, and it runs fine under a standard user account.
