Continuous System Change Monitoring
Free users can manually verify important system files, security
settings, and credential protections. Premium goes further by
allowing ProtectKit to keep monitoring supported areas over time.
This matters because a security setting can be correct today and
changed later. Continuous monitoring is designed to help detect
important changes without requiring the user to remember to run
the same check repeatedly.
Continuous Live Connection Monitoring
A network snapshot tells you what is connected at the moment you
look. Continuous monitoring is more useful when activity is brief,
intermittent, or happens while you are doing something else.
Premium is designed to keep watching supported connection activity
so potentially important events are less likely to disappear simply
because you were not looking at the Live Connections page at that moment.
Real-Time Security Alerts
Premium can alert you when supported continuous-monitoring features
detect activity that deserves attention. The goal is not to frighten
users with vague warnings, but to provide enough context to understand
what happened and why ProtectKit surfaced it.
Advanced Investigation
ProtectKit is built around evidence. Depending on the feature,
investigations can include executable paths, publishers, digital
signatures, hashes, processes, services, local and remote addresses,
ports, connection state, and external reputation information.
Premium unlocks deeper investigation capabilities where the Free
edition intentionally provides a more limited workflow.
Intrusion Detection
Intrusion Detection is intended for users who want ProtectKit to
continuously watch for suspicious connection activity rather than
requiring them to manually inspect network information.
Detected activity can be logged and surfaced for review, with
alerts and supported response options when appropriate.
Spyware & Stalkerware Investigation
Some unwanted monitoring software may not look like traditional
malware. ProtectKit's spyware and stalkerware workflow is designed
to examine suspicious indicators and explain the evidence rather than
immediately labeling every unusual program as malicious.
This careful approach matters because removing monitoring software
without understanding the situation can sometimes destroy evidence,
break legitimate software, or create other problems.
Ransomware Behavior Protection
Ransomware protection focuses on suspicious behavior, especially
patterns involving rapid or unusual file activity. The goal is to
identify behavior that deserves immediate attention even when a
simple file-name or signature check would not tell the whole story.
Malicious Code Protection
Malicious Code Protection adds another layer of analysis for
suspicious code and behavior. It is designed to complement, not
replace, Microsoft Defender and other Windows security technologies.
ProtectKit's role is to add visibility, evidence, explanation, and
practical next steps around suspicious activity.
Advanced Windows Hardening
Windows includes many security-sensitive settings that are easy for
ordinary users to overlook. ProtectKit brings important hardening
checks together and explains what the settings mean before users
decide whether to change them.
Premium provides access to the more advanced hardening capabilities.
Unlimited Scan History
A single scan shows current results. History provides context.
Premium allows users to retain a deeper record of supported scan
activity so they can compare findings and better understand how a
system changes over time.