Real-time threat detection
Continuous monitoring of file system activity with instant detection and removal of malware, trojans, ransomware and potentially unwanted programs. Dual-engine scanning on ClamAV and YARA runs entirely in-process.
Seven x2y tools remain free. Code Leak Detector is $29 as a one-time purchase.
View productsWindows Security Software
Comprehensive security suite for Windows. Real-time protection, threat intelligence with 5,500+ signatures, persistence auditing, and network monitoring. Protects your system without slowing it down.
Free — no account, no subscription, no telemetry. Donationware since July 2026.
At a glance
Signed installers with published SHA-256 checksums. No activation key, no account, no first-run prompt.
Key features
Continuous monitoring of file system activity with instant detection and removal of malware, trojans, ransomware and potentially unwanted programs. Dual-engine scanning on ClamAV and YARA runs entirely in-process.
Offline signature bundles sourced from MalwareBazaar (recent and full feeds), URLhaus malicious URL detection, OpenPhish phishing protection, and the ClamAV freshclam database. Updated manually — the app never phones home.
Deep analysis of startup entries, registry run keys, scheduled tasks, services and browser extensions. Identifies persistence mechanisms used by malware to survive reboots — before they activate.
Real-time process mapping and traffic flow visualisation. See every active connection — protocol, remote address, PID, process name, state and risk level — at a glance. Export to CSV for forensic analysis.
Suspicious files are isolated in an encrypted local vault — not deleted, not uploaded. Review, restore or permanently remove at your discretion. Full audit trail of every quarantine action.
Compute and verify file hashes locally against known-good baselines. Integrity monitoring across 1,024+ watchpaths alerts on unexpected modification of binaries, configs and boot paths.
Threat sources
RECENT + FULL FEEDS
MALICIOUS URL DETECTION
PHISHING PROTECTION
FRESHCLAM DATABASE
Specifications
| Product | x2y AV Ultimate |
|---|---|
| Version | v8.5.0 |
| Platform | Windows 10, Windows 11 |
| Architecture | x64 (64-bit) |
| Signatures | 5,500+ (offline bundle) |
| Engines | ClamAV 0.105, YARA 4.5 |
| Threat intel | MalwareBazaar, URLhaus, OpenPhish, ClamAV freshclam |
| Watchpaths | 1,024+ integrity monitor paths |
| Network monitor | Real-time TCP/UDP with process mapping |
| Quarantine | Encrypted local vault, restorable |
| Hash algorithms | SHA-256, MD5 |
| Export | CSV (network connections, scan reports) |
| Telemetry | 0 bytes — verified continuously |
| Account required | None — ever |
| Price | Free — donationware since Jul 2026 |
| Developer | x2y Devs Tools Ltd, Nairobi, Kenya |
Quick start
Get the installer from Microsoft Store, itch.io or GitHub. Verify the SHA-256 checksum against the published value.
Run the signed installer. No administrator privileges required for standard installs. No account creation, no activation key.
Signature bundles load from disk automatically. ClamAV and YARA initialise with 5,500+ offline signatures. The integrity monitor arms 1,024+ watchpaths.
Run a full scan, enable real-time protection, or open the Network Monitor. Every verdict is reached locally. Telemetry sent: 0 B.
Downloads
Changelog
Threat intelligence refresh to 5,500+ signatures. New persistence auditor module. Network activity monitor with real-time process mapping and traffic flow graph. Hardened installer with published SHA-256 checksums.
New dual-engine detection pipeline (ClamAV + YARA). Integrity monitor with configurable watchpaths. Quarantine vault with encrypted local storage.
Initial public launch. Core scanning engine, basic threat detection, Windows 10/11 support.
Security model
Every claim above is independently verifiable. Run Wireshark, Fiddler, GlassWire, or your operating system's firewall logs while using x2y AV Ultimate. You will observe zero outbound connections attributable to the application. We encourage this verification.
| Telemetry | 0 bytes collected |
|---|---|
| Account | None required — ever |
| Data egress | None by design |
| Engines | ClamAV 0.105 · YARA 4.5 |
| Threat feeds | Offline bundles only |
| Quarantine | Encrypted local vault |
| Installer | Signed · SHA-256 published |
| Verification | Any network monitor |
Under the hood
Every scan in x2y AV Ultimate is answered by two independent engines running in the same process. ClamAV 0.105 supplies the traditional signature match against bytecode and CVD-format databases; YARA 4.5 supplies the rule-based layer that catches families, packers and behavioural artefacts a hash list will never see. A file is only reported clean when both engines agree, and both engines read from bundles already on your disk.
Because there is no query to send, verdict latency is the cost of reading a file — not the cost of a round trip. That matters on machines with slow or metered links, and it matters when the network is deliberately unavailable.
The shipped bundle combines ClamAV freshclam databases with curated samples from MalwareBazaar (recent and full feeds), malicious URL data from URLhaus and phishing indicators from OpenPhish. Those feeds are the same public sources commercial products index; the difference is delivery. Here they are downloaded as a bundle, pinned to a release and verified by checksum before the app loads them.
The trade-off is honest and documented: offline signatures age. A commercial cloud scanner can answer a brand-new sample within minutes; x2y AV Ultimate answers once you refresh the bundle. For air-gapped or intermittently connected machines, that trade — a known, dated detection set you can audit, versus an opaque live one you cannot — is usually the right one.
Malware survives reboots by writing itself into startup entries, registry run keys, scheduled tasks, services and browser extensions. The persistence auditor enumerates exactly those locations and shows what each entry points at, so a suspicious scheduled task is visible even when its payload is not yet detected by any engine.
The integrity monitor watches 1,024+ configured watchpaths — binaries, boot paths and configuration files — and alerts on unexpected modification. Combined with local SHA-256 and MD5 hashing, that gives you a baseline you control rather than a reputation service you trust blindly.
Detections are not deleted and never uploaded. Objects are moved into an encrypted local vault with a full audit trail, so you can review, restore or permanently remove each one. Every action, verdict and engine response is also exportable as CSV for your own records or an incident timeline.
How it works
Download the signed installer from Microsoft Store, itch.io or GitHub Releases and compare its SHA-256 hash with the value published on the release page. Standard installs need no administrator privileges, and there is no activation step to complete.
ClamAV and YARA initialise against the offline signature bundle. The integrity monitor arms its watchpaths. No configuration wizard asks for an email address, a cloud region or permission to send samples.
Run a quick scan, a full scan or a custom scope such as a single project directory. Heuristics and both engines run in-process; results stream into the same view as the scan progresses.
Detections move to the encrypted quarantine vault with a timestamped entry in the audit trail. Clean verdicts, engine versions and per-file timings can be exported to CSV for reporting.
| Detection path | ClamAV signature match → YARA rule match → heuristic verdict |
|---|---|
| Signature load | Offline bundle, verified at startup |
| Integrity baseline | 1,024+ watchpaths, alert on modification |
| Quarantine | Encrypted local vault, restorable |
| Reporting | CSV export of scans and network connections |
| Update model | Manual bundle refresh, pinned per release |
Who it is for
Six environments we designed against, because a cloud-only scanner simply stops being useful in all of them.
Labs, OT benches and government or finance workstations with no outbound path. The bundle is carried in on removable media and the app never expects to reach a vendor.
A machine that spends weeks off a corporate network still gets a dated, auditable detection set instead of the degraded mode a cloud product falls back to.
Endpoint coverage for a studio, agency or NGO across a handful of Windows machines, with CSV exports that are good enough for an insurance or compliance review.
The persistence auditor and integrity baseline tell you what changed and where a payload hides, so a rebuild decision is informed rather than hopeful.
Scan a build tree before it ships. Verdicts come from engines whose versions you pinned, so results are reproducible across runs.
A parent or partner setup where the goal is quiet protection: no upsell dialogs, no telemetry consent banners, no renewal notices.
Prerequisites
| Requirement | Minimum | Recommended |
|---|---|---|
| Operating system | Windows 10 (64-bit) | Windows 11 (64-bit) |
| Architecture | x64 | x64 with an SSD for faster full scans |
| Privileges | Standard install requires no administrator rights | Portable archive run from a user folder for kiosk or lab machines |
| Network | None — the app is fully functional offline | A connection only to download the installer and a fresh signature bundle |
| Other antivirus | Do not run two real-time scanners at once | Exclude the x2y quarantine folder from any remaining on-access scanner |
| Storage | Room for the installer plus the offline signature bundle | Keep free space for scan caches and CSV reports you export |
| Verification tools | Any SHA-256 hash utility | PowerShell Get-FileHash plus a network monitor to confirm zero egress |
Context
Three honest columns. Where x2y is weaker, the table says so.
| Capability | x2y AV Ultimate | Cloud subscription AV | Windows Defender only |
|---|---|---|---|
| Detection source | Pinned ClamAV + YARA bundles you can inspect | Vendor cloud + local definitions, opaque | Microsoft definitions, opaque |
| Behaviour offline | Full functionality | Degraded until definitions refresh | Full functionality |
| Zero-day coverage | Weaker by design: relies on dated rules and heuristics | Strongest — live telemetry from millions of hosts | Strong — cloud-delivered protection |
| Data egress | 0 bytes, verifiable | Samples, metadata and diagnostics per policy | Cloud lookups and automatic sample submission |
| Account | None, ever | Vendor account usually required | Often tied to a Microsoft account |
| Cost | Free · donationware | Recurring per-device subscription | Included with Windows |
| Auditability | Open engines, published checksums, CSV exports | Closed engines | Closed engines |
Questions
Get-FileHash .\x2y-av-ultimate-v8.5.0-setup.exe -Algorithm SHA256 in PowerShell and compare the output. If it differs, delete the file and report it to security@x2ydevs.xyz.Documentation
Ready to protect your system
No account. No subscription. No telemetry. Just comprehensive Windows security that works when the network is off.
| Version | v8.5.0 |
|---|---|
| Platform | Windows 10 / 11 |
| Price | Free — donationware |
| Telemetry | 0 bytes |