Seven x2y tools remain free. Code Leak Detector is $29 as a one-time purchase.

View products

Windows Security Software

x2y AV Ultimate

v8.5.0

Comprehensive security suite for Windows. Real-time protection, threat intelligence with 5,500+ signatures, persistence auditing, and network monitoring. Protects your system without slowing it down.

WINDOWS 10/115,500+ SIGNATURES100% OFFLINEZERO TELEMETRY

Free — no account, no subscription, no telemetry. Donationware since July 2026.

At a glance

  • Versionv8.5.0
  • PlatformWindows 10 / 11 · x64
  • EnginesClamAV 0.105 + YARA 4.5
  • Signatures5,500+ offline bundle
  • PriceFree · donationware
  • Telemetry0 bytes

Signed installers with published SHA-256 checksums. No activation key, no account, no first-run prompt.

Key features

Everything you need to protect a Windows machine, nothing you don't

Real-time threat detection

Continuous monitoring of file system activity with instant detection and removal of malware, trojans, ransomware and potentially unwanted programs. Dual-engine scanning on ClamAV and YARA runs entirely in-process.

Threat intelligence — 5,500+ signatures

Offline signature bundles sourced from MalwareBazaar (recent and full feeds), URLhaus malicious URL detection, OpenPhish phishing protection, and the ClamAV freshclam database. Updated manually — the app never phones home.

Persistence auditor

Deep analysis of startup entries, registry run keys, scheduled tasks, services and browser extensions. Identifies persistence mechanisms used by malware to survive reboots — before they activate.

Network activity monitor

Real-time process mapping and traffic flow visualisation. See every active connection — protocol, remote address, PID, process name, state and risk level — at a glance. Export to CSV for forensic analysis.

Quarantine vault

Suspicious files are isolated in an encrypted local vault — not deleted, not uploaded. Review, restore or permanently remove at your discretion. Full audit trail of every quarantine action.

Hash lookup — SHA256 / MD5

Compute and verify file hashes locally against known-good baselines. Integrity monitoring across 1,024+ watchpaths alerts on unexpected modification of binaries, configs and boot paths.

Threat sources

Open, auditable intelligence feeds

MalwareBazaar

RECENT + FULL FEEDS

URLhaus

MALICIOUS URL DETECTION

OpenPhish

PHISHING PROTECTION

ClamAV

FRESHCLAM DATABASE

How threat intel works. All signature feeds are downloaded as offline bundles and shipped with each release. You can also update them manually from the original sources. The application itself never connects to MalwareBazaar, URLhaus, OpenPhish or ClamAV servers — verification is possible with any network monitor.

Specifications

Technical details

x2y AV Ultimate specifications
Productx2y AV Ultimate
Versionv8.5.0
PlatformWindows 10, Windows 11
Architecturex64 (64-bit)
Signatures5,500+ (offline bundle)
EnginesClamAV 0.105, YARA 4.5
Threat intelMalwareBazaar, URLhaus, OpenPhish, ClamAV freshclam
Watchpaths1,024+ integrity monitor paths
Network monitorReal-time TCP/UDP with process mapping
QuarantineEncrypted local vault, restorable
Hash algorithmsSHA-256, MD5
ExportCSV (network connections, scan reports)
Telemetry0 bytes — verified continuously
Account requiredNone — ever
PriceFree — donationware since Jul 2026
Developerx2y Devs Tools Ltd, Nairobi, Kenya

Quick start

From download to protected in four steps

  1. 01

    Download and verify

    Get the installer from Microsoft Store, itch.io or GitHub. Verify the SHA-256 checksum against the published value.

  2. 02

    Install

    Run the signed installer. No administrator privileges required for standard installs. No account creation, no activation key.

  3. 03

    Load engines

    Signature bundles load from disk automatically. ClamAV and YARA initialise with 5,500+ offline signatures. The integrity monitor arms 1,024+ watchpaths.

  4. 04

    Scan and monitor

    Run a full scan, enable real-time protection, or open the Network Monitor. Every verdict is reached locally. Telemetry sent: 0 B.

CLIx2y-av --scan C:\Projects --engines clamav,yara --report localresolving engines ............ clamav 0.105 · yara 4.5loading signatures ........... 5,500+ · offline bundleintegrity monitor ............ armed · 1,024 watchpathsnetwork egress ............... blocked by designscanning 12,847 files ........ done in 41.2 s✓ verdict: CLEAN · threats 0 · telemetry sent 0 B

Downloads

Get x2y AV Ultimate v8.5.0

Verify before installing. Every release is signed and accompanied by a published SHA-256 checksum. Compare the hash of your download against the value on the GitHub release page before running the installer.

Changelog

Release history

MAR 2026v8.5.0

Threat intelligence refresh to 5,500+ signatures. New persistence auditor module. Network activity monitor with real-time process mapping and traffic flow graph. Hardened installer with published SHA-256 checksums.

DEC 2025v7.0.0

New dual-engine detection pipeline (ClamAV + YARA). Integrity monitor with configurable watchpaths. Quarantine vault with encrypted local storage.

OCT 2025v6.x

Initial public launch. Core scanning engine, basic threat detection, Windows 10/11 support.

Security model

Privacy enforced by architecture, not promises

Data policy. Telemetry: 0 bytes collected. Account required: none, ever. Data egress: none by design. Scan engines: ClamAV and YARA (open source). Threat intel: MalwareBazaar, URLhaus, OpenPhish (loaded offline). Updates: signed releases via GitHub with published SHA-256 checksums. Licence: free, donationware.

Every claim above is independently verifiable. Run Wireshark, Fiddler, GlassWire, or your operating system's firewall logs while using x2y AV Ultimate. You will observe zero outbound connections attributable to the application. We encourage this verification.

Security manifest
Telemetry0 bytes collected
AccountNone required — ever
Data egressNone by design
EnginesClamAV 0.105 · YARA 4.5
Threat feedsOffline bundles only
QuarantineEncrypted local vault
InstallerSigned · SHA-256 published
VerificationAny network monitor

Under the hood

How x2y AV Ultimate reaches a verdict without a network connection

Two engines, one local pipeline

Every scan in x2y AV Ultimate is answered by two independent engines running in the same process. ClamAV 0.105 supplies the traditional signature match against bytecode and CVD-format databases; YARA 4.5 supplies the rule-based layer that catches families, packers and behavioural artefacts a hash list will never see. A file is only reported clean when both engines agree, and both engines read from bundles already on your disk.

Because there is no query to send, verdict latency is the cost of reading a file — not the cost of a round trip. That matters on machines with slow or metered links, and it matters when the network is deliberately unavailable.

What 5,500+ offline signatures actually means

The shipped bundle combines ClamAV freshclam databases with curated samples from MalwareBazaar (recent and full feeds), malicious URL data from URLhaus and phishing indicators from OpenPhish. Those feeds are the same public sources commercial products index; the difference is delivery. Here they are downloaded as a bundle, pinned to a release and verified by checksum before the app loads them.

The trade-off is honest and documented: offline signatures age. A commercial cloud scanner can answer a brand-new sample within minutes; x2y AV Ultimate answers once you refresh the bundle. For air-gapped or intermittently connected machines, that trade — a known, dated detection set you can audit, versus an opaque live one you cannot — is usually the right one.

Persistence and integrity, not just files

Malware survives reboots by writing itself into startup entries, registry run keys, scheduled tasks, services and browser extensions. The persistence auditor enumerates exactly those locations and shows what each entry points at, so a suspicious scheduled task is visible even when its payload is not yet detected by any engine.

The integrity monitor watches 1,024+ configured watchpaths — binaries, boot paths and configuration files — and alerts on unexpected modification. Combined with local SHA-256 and MD5 hashing, that gives you a baseline you control rather than a reputation service you trust blindly.

Quarantine you can audit

Detections are not deleted and never uploaded. Objects are moved into an encrypted local vault with a full audit trail, so you can review, restore or permanently remove each one. Every action, verdict and engine response is also exportable as CSV for your own records or an incident timeline.

How it works

From installer to first verdict, entirely on your machine

01

Verify, then install

Download the signed installer from Microsoft Store, itch.io or GitHub Releases and compare its SHA-256 hash with the value published on the release page. Standard installs need no administrator privileges, and there is no activation step to complete.

02

Engines load from disk

ClamAV and YARA initialise against the offline signature bundle. The integrity monitor arms its watchpaths. No configuration wizard asks for an email address, a cloud region or permission to send samples.

03

Scan on your terms

Run a quick scan, a full scan or a custom scope such as a single project directory. Heuristics and both engines run in-process; results stream into the same view as the scan progresses.

04

Act on verdicts locally

Detections move to the encrypted quarantine vault with a timestamped entry in the audit trail. Clean verdicts, engine versions and per-file timings can be exported to CSV for reporting.

Technical summary
Detection pathClamAV signature match → YARA rule match → heuristic verdict
Signature loadOffline bundle, verified at startup
Integrity baseline1,024+ watchpaths, alert on modification
QuarantineEncrypted local vault, restorable
ReportingCSV export of scans and network connections
Update modelManual bundle refresh, pinned per release
Verify the silence yourself. Launch the app under Wireshark, GlassWire, mitmproxy or your Windows firewall log. There is no analytics endpoint, no crash uploader and no licence ping to find — the update path is a bundle you download on purpose.

Who it is for

Situations where an offline engine is the only kind that works

Six environments we designed against, because a cloud-only scanner simply stops being useful in all of them.

Air-gapped and restricted networks

Labs, OT benches and government or finance workstations with no outbound path. The bundle is carried in on removable media and the app never expects to reach a vendor.

Field laptops and travel

A machine that spends weeks off a corporate network still gets a dated, auditable detection set instead of the degraded mode a cloud product falls back to.

Small teams without an EDR budget

Endpoint coverage for a studio, agency or NGO across a handful of Windows machines, with CSV exports that are good enough for an insurance or compliance review.

Incident triage before you reimage

The persistence auditor and integrity baseline tell you what changed and where a payload hides, so a rebuild decision is informed rather than hopeful.

Release and build machines

Scan a build tree before it ships. Verdicts come from engines whose versions you pinned, so results are reproducible across runs.

Home machines you are responsible for

A parent or partner setup where the goal is quiet protection: no upsell dialogs, no telemetry consent banners, no renewal notices.

Prerequisites

What your machine needs before the first scan

x2y AV Ultimate specifications and prerequisites
RequirementMinimumRecommended
Operating systemWindows 10 (64-bit)Windows 11 (64-bit)
Architecturex64x64 with an SSD for faster full scans
PrivilegesStandard install requires no administrator rightsPortable archive run from a user folder for kiosk or lab machines
NetworkNone — the app is fully functional offlineA connection only to download the installer and a fresh signature bundle
Other antivirusDo not run two real-time scanners at onceExclude the x2y quarantine folder from any remaining on-access scanner
StorageRoom for the installer plus the offline signature bundleKeep free space for scan caches and CSV reports you export
Verification toolsAny SHA-256 hash utilityPowerShell Get-FileHash plus a network monitor to confirm zero egress
Nothing here is a gate. There is no hardware requirement for a cloud lookups cache, no account to create and no minimum signature freshness enforced by the app. If you deliberately run an old bundle, the app still works — it just tells you what it was pinned to.

Context

How an offline scanner differs from the alternatives

Three honest columns. Where x2y is weaker, the table says so.

Comparison of local, cloud and built-in scanning approaches
Capabilityx2y AV UltimateCloud subscription AVWindows Defender only
Detection sourcePinned ClamAV + YARA bundles you can inspectVendor cloud + local definitions, opaqueMicrosoft definitions, opaque
Behaviour offlineFull functionalityDegraded until definitions refreshFull functionality
Zero-day coverageWeaker by design: relies on dated rules and heuristicsStrongest — live telemetry from millions of hostsStrong — cloud-delivered protection
Data egress0 bytes, verifiableSamples, metadata and diagnostics per policyCloud lookups and automatic sample submission
AccountNone, everVendor account usually requiredOften tied to a Microsoft account
CostFree · donationwareRecurring per-device subscriptionIncluded with Windows
AuditabilityOpen engines, published checksums, CSV exportsClosed enginesClosed engines

Questions

What people ask before they install

It is designed to be the scanner you control, not to win a detection-rate contest against a vendor with global telemetry. Run one real-time scanner at a time: if you enable x2y AV Ultimate, disable competing on-access protection so two filters do not fight over the same files. On-demand scanning of a specific folder is where this tool is strongest.
Because that number is a curated, offline, inspectable bundle rather than a marketing total of every hash in a cloud database. The bundle combines ClamAV freshclam data with MalwareBazaar samples, URLhaus malicious URLs and OpenPhish phishing indicators, and you can open it and read what is inside. Dated but auditable is a real trade-off, and we state it plainly.
Manually. Download the updated bundle from the release page, place it where the app expects it and restart. The application never connects to MalwareBazaar, URLhaus, OpenPhish or ClamAV servers on its own — that separation is the point of the design.
Into an encrypted quarantine vault on your disk, never to us. Each entry records the verdict, the engine that raised it and the timestamp, and you can restore or permanently delete it. Nothing is uploaded for analysis because there is no upload path to analyse.
Yes. Since July 2026 every product in the suite except Code Leak Detector is free for personal and commercial use under a donationware model, with no seat limits and no licence keys. See the Terms of Use.
Real-time work here is local file monitoring plus two engines running in-process, with no cloud round trip waiting in the scan path. Full scans are I/O bound, so an SSD and a sensibly scoped watchpath list matter more than CPU. You can also schedule scans for quiet hours.
Every release publishes a SHA-256 checksum on GitHub and itch.io. Run Get-FileHash .\x2y-av-ultimate-v8.5.0-setup.exe -Algorithm SHA256 in PowerShell and compare the output. If it differs, delete the file and report it to security@x2ydevs.xyz.

Ready to protect your system

Download x2y AV Ultimate — free, offline, forever

No account. No subscription. No telemetry. Just comprehensive Windows security that works when the network is off.

Summary
Versionv8.5.0
PlatformWindows 10 / 11
PriceFree — donationware
Telemetry0 bytes