Getting Started
Learn the basics before exploring ProtectKit's deeper security tools.
- Installing ProtectKit
- First launch
- Navigating the application
- Administrator privileges
- Free and Premium editions
Learn how to use ProtectKit's Windows security, investigation, monitoring, privacy, maintenance, and recovery tools. This Help Center also explains what ProtectKit findings mean, why administrator access may sometimes be required, and how to respond when something needs attention.
Start with a category below. Dedicated help articles can be added for individual ProtectKit pages as the Help Center grows.
Learn the basics before exploring ProtectKit's deeper security tools.
Learn how to interpret ProtectKit statuses, evidence, and recommendations.
Help for ProtectKit's core Windows security and hardening tools.
Understand processes, services, startup entries, connections, and suspicious activity.
Learn what ProtectKit's behavior-focused protection features are designed to detect.
Review connected-device security and understand what ProtectKit reports.
Use ProtectKit's privacy, cleanup, repair, optimization, and recovery tools safely.
Learn what ProtectKit records and how to review or export supported information.
Understand Premium access, monthly and yearly plans, and activation.
Start here when ProtectKit or a Windows operation does not work as expected.
If the Help Center does not solve the problem, contact ProtectKit Support.
ProtectKit brings many Windows security and maintenance functions together, but you do not need to use every feature immediately.
Install ProtectKit from its official Microsoft Store listing. Using the official listing helps ensure you are installing the intended ProtectKit package.
The Dashboard is the best starting point for understanding the current state of supported protections. Review the protection summary, recent activity, items needing attention, scan information, and monitoring status before deciding what to investigate.
ProtectKit can surface settings and system information that may look unfamiliar. An unfamiliar process, service, connection, or startup entry is not automatically malicious.
Review the available evidence and explanation before disabling, deleting, blocking, or changing anything.
ProtectKit normally runs without requiring administrator privileges for every action. Some Windows operations require elevation because Windows restricts access to security-sensitive settings and system changes.
When administrator access is required, it does not automatically mean something is wrong. It usually means the requested Windows operation needs elevated permission.
ProtectKit does not replace Microsoft Defender and does not guarantee that a computer is free from malware or other threats. Its purpose is to improve visibility, configuration, investigation, monitoring, explanation, and response.
ProtectKit is designed to give context around a finding so you can make a better decision instead of reacting to a vague warning.
Start by identifying exactly what ProtectKit is referring to. It may be a process, service, startup entry, connection, Windows setting, security protection, file, or connected device.
ProtectKit should explain the security relevance of the item. For example, a startup program matters because it can run automatically, while a remote connection matters because a process is communicating with another system.
Depending on the feature, evidence may include executable paths, publishers, digital signatures, hashes, service information, connection details, Windows security status, and reputation information.
The appropriate action depends on the evidence. Sometimes the correct response is to change a setting. Sometimes it is to investigate further. Sometimes the safest action is to leave a legitimate item alone.
Use the Defender page to review protection information, update Microsoft Defender, and launch supported Windows scans such as Quick, Full, Custom, and Offline scans.
ProtectKit uses Defender as a Windows security technology rather than pretending to replace it.
Review firewall profiles and individual rules before making changes. Disabling the wrong rule can break applications or Windows features, while overly permissive rules can increase exposure.
Emergency network lockdown is intended for situations where quickly restricting network traffic is appropriate.
DNS Protection helps review the computer's DNS configuration and provides supported secure DNS options. DNS filtering can reduce exposure to some malicious destinations, but it is not a substitute for antivirus, careful browsing, or other security layers.
Hardening checks cover important Windows security settings such as SmartScreen, SMBv1, AutoRun, PowerShell logging, virtualization-based security, HVCI, Credential Guard, and other supported controls.
Review explanations before applying changes because security settings can affect compatibility on some systems.
System Change Monitor verifies supported system files, security settings, and credential protections. Free users can perform supported manual checks. Premium adds continuous monitoring for supported areas.
A manual check tells you what ProtectKit sees when you run it. Continuous monitoring is designed to keep watching supported activity over time so important changes can be surfaced without relying entirely on the user to repeat the same check.
Unknown does not mean malicious. Use multiple pieces of evidence before deciding whether something should be blocked, disabled, or removed.
Live Connections shows supported TCP and UDP activity together with process, address, port, protocol, state, signature, and other available information.
Use investigation tools to identify the executable, review its signature and hash, examine the remote destination, and determine whether the connection makes sense for the program involved.
Startup programs can launch automatically when Windows starts or when you sign in. Review the publisher, signature, source, executable path, and other evidence before pausing or removing an entry.
Windows services often run in the background and many legitimate services have unfamiliar names. ProtectKit provides status, trust, executable-path, signature, publisher, and investigation information to help distinguish unfamiliar from genuinely suspicious.
Intrusion Detection is a Premium protection feature. It is designed to continuously monitor for suspicious connection activity, log detected events, alert you to potential threats, and provide supported response options.
Free users may be able to view the page and learn about the capability, but the active protection functionality requires Premium.
This workflow is intended to help identify suspicious software or behavior associated with unwanted monitoring. The advanced scan is a Premium capability.
Treat results carefully. Suspicious indicators should be investigated using the surrounding evidence rather than treated as automatic proof that someone is spying on the computer.
Some investigation features may use internet-based reputation or information services. Those lookups require an internet connection and may send the minimum information needed for the lookup, such as a file hash or remote address, to the selected service.
Ransomware behavior protection focuses on suspicious patterns such as unusual or high-volume file activity. A behavior-based signal is a reason to investigate, not automatic proof that ransomware is present.
Malicious Code Protection adds another analysis layer for suspicious code or behavior. It is intended to complement Windows security technologies while providing additional evidence and explanation.
Premium monitoring features can surface supported security events while ProtectKit is monitoring. Read the alert details and evidence before deciding on a response.
Avoid deleting files or disabling Windows components solely because one signal looks unusual. Stronger decisions come from combining multiple pieces of evidence and understanding the role of the affected item.
Use USB Security to review supported information about connected USB devices. If you do not recognize a device, investigate before assuming it is malicious. Many internal and external components can appear as USB devices.
Bluetooth Security provides visibility and guidance around supported Bluetooth information and connected-device activity. Review unfamiliar devices and remove or disable access only when you understand what the device is and why it is present.
Cleanup workflows are intended to remove supported temporary or unnecessary data. Review what the selected action does before running it.
Repair workflows can invoke trusted Windows repair mechanisms. Some repairs can take time and should not be interrupted once Windows has begun the operation.
Optimization tools use supported Windows maintenance operations. ProtectKit is not designed around exaggerated “one-click speed boost” claims. Results depend on the actual condition of the computer.
A restore point can provide an important recovery path before some system changes. ProtectKit emphasizes recovery options because a safe security or maintenance workflow should consider how a change can be reversed.
ProtectKit's Privacy page helps review supported Windows privacy-related settings. For information about ProtectKit's own data practices, read the separate Privacy Policy.
Some Windows changes do not fully take effect until the computer is restarted. If ProtectKit indicates that a restart is required, save your work before restarting Windows.
ProtectKit records important supported application and security activity in local logs. Logs can help reconstruct what happened, review earlier actions, and support troubleshooting.
Supported pages can export information for later review. Reports may contain computer names, paths, process information, network addresses, or other system details depending on what was exported.
Review exported logs and screenshots before sending them to anyone. Remove passwords, authentication tokens, private keys, recovery codes, or other information you consider sensitive.
History helps provide context across multiple checks instead of treating every scan as an isolated event. Premium provides expanded or unlimited supported scan-history capability.
Many failed security or maintenance operations are caused by Windows permissions, network availability, another operation already running, or a Windows component returning an error.
Retry the specific operation with the requested administrator permission. Windows restricts many security-sensitive settings and repair operations. Do not run the entire application elevated unless the workflow specifically requires it.
Read the error ProtectKit reports, verify that another Windows servicing or security operation is not already running, restart Windows if appropriate, and try the operation again. Persistent Windows servicing errors may require Windows-specific troubleshooting beyond ProtectKit itself.
Confirm the PC has internet access. External investigation services can also be temporarily unavailable, rate-limited, or unable to return information for a particular hash or address.
Treat the result as something to review, especially when the evidence is incomplete. Check the executable path, publisher, signature, hash, process or service role, and other available evidence. Report repeatable false positives to ProtectKit Support so they can be investigated.
Confirm that you are using the account or purchase information associated with your ProtectKit Premium subscription and that the computer has internet access when activation verification requires it. If Premium still does not activate, contact ProtectKit Support with non-sensitive purchase details.
Contact ProtectKit Support at support@getprotectkit.com. Explain what you were doing, what you expected to happen, what actually happened, and any error message shown. Screenshots or exported logs can help, but review attachments for sensitive information before sending them.
Contact ProtectKit Support for product questions, bug reports, licensing problems, feedback, or help with a ProtectKit feature.