Real-Time File Protection
Watches Downloads, Temp, your whole user profile and any USB drive you plug in. Anything new or changed is scanned within milliseconds, before you get a chance to open it.

Real-time malware protection, malicious-site blocking, an interactive firewall and a ransomware shield, in one free Windows app. It works alongside Microsoft Defender rather than replacing it.
🆓 Free · v1.0.0 · 47 MB · Windows 10 & 11 (64-bit) · No account, no tracking
Run a scan, quarantine what it finds, switch a shield off and watch the dashboard react. This is a browser simulation of the real app — nothing on your computer is touched.
This PC is protected
Last scan: today · Signatures: today
Real-time file protection
OnNew and changed files are checked as they land
Web protection
On427,457 harmful domains on the block list
Ransomware shield
OnBait files and mass-change detection
Firewall
OnWindows Firewall plus connection watch
Device control
OnUSB drives are scanned on insert
Startup guard
OnNew auto-start entries are caught
427,457
Blocked domains
25
Behaviour rules
0
In quarantine
0
Threats handled
Watches Downloads, Temp, your whole user profile and any USB drive you plug in. Anything new or changed is scanned within milliseconds, before you get a chance to open it.
427,000+ malware and phishing domains are blocked in every browser, with no extension to install. Refreshed automatically from public threat feeds several times a day.
Hidden bait files sit in your Documents, Pictures and Desktop. The moment anything touches them, or starts rewriting files in bulk, the process responsible is identified and stopped.
Choose how new programs reach the internet: log it quietly, ask you the first time, or lock the machine down so nothing unapproved gets out. Plus a block-all-inbound panic switch.
Every removable drive is scanned on insert and autorun.inf is neutralised automatically. USB storage can also be blocked outright on machines that should never accept a stick.
Every Run key, startup folder and logon entry is baselined. When something new adds itself, you are told and the file behind it is scanned before it ever gets to run.
13 checks on the settings attackers rely on being wrong: firewall, UAC, SMBv1, RDP, Remote Registry, Guest account, AutoPlay, BitLocker, open ports and more, with one-click fixes.
See every device on your Wi-Fi, scan any of them for open ports, and watch which programs on your PC are talking to the internet right now.
Every file is fingerprinted and checked against a signature list refreshed from public malware feeds.
ShieldVane calls Microsoft's own scan engine through AMSI, so it inherits Defender's continuously updated definitions instead of inventing its own.
Encoded PowerShell, macro droppers, disguised double extensions, credential dumpers, backup deletion, code injection, crypto miners and more.
Bait files and a mass-change detector catch encryption attacks that no signature has ever seen.
Security software should be honest about its limits. Here are ShieldVane's, up front.
ShieldVane leaves Defender switched on and running, and uses its engine. Two layers beat one, and you never end up with a machine that has no protection at all because a third-party tool took over and then failed.
A file-system driver would need an EV certificate and Microsoft attestation signing, which is a recurring yearly cost. ShieldVane detects and contains in user mode instead, which covers the practical cases without that overhead.
Registering there requires membership of the Microsoft Virus Initiative, which requires paid independent lab certification. ShieldVane runs as a companion tool instead, which is also the safer arrangement.
ShieldVane for Windows
Version 1.0.0 · 47 MB · Windows 10 & 11, 64-bit
⬇ Download ShieldVane-Setup-1.0.0.exeSHA256 35970f6f155c07eaaab800784c91a97fa13b28c5089ec5dad0c0ede46061de03
The installer is not code-signed yet, so Windows SmartScreen may show a blue "Windows protected your PC" box. Click More info → Run anyway. That warning appears for every unsigned installer, not because anything is wrong with this one. Check the hash above if you want to be sure the file is the one published here.
A single 47 MB file. Nothing else needs to be installed first — the .NET runtime is bundled.
Windows asks for administrator rights, because the background service and the site blocker both need them.
Protection starts immediately and again on every boot. The tray icon next to the clock opens the dashboard.
Yes. No account, no licence key, no trial timer, no telemetry. It costs nothing to run because it uses the scan engine Windows already ships with and public threat feeds.
Real-time scanning only touches files as they are created or changed, and skips anything already checked. Gamer mode pauses notifications and scheduled work entirely while you play.
A detection inside Windows or Program Files is reported, never removed automatically, and signed system binaries are trusted rather than scanned by the behaviour rules. Anything that is quarantined can be restored with one click.
Nothing leaves your machine. The only outbound traffic is downloading threat lists. Scan results, logs and quarantined files stay in a folder on your own PC.
Normal Windows uninstall. It removes the service and takes its entries back out of your hosts file on the way out, so nothing is left behind.
ShieldVane can be deployed silently across many machines, with your own policy baked in. Ask about a managed build.