Skip to content

Repository files navigation

شعار blazma.nt

blazma.nt

مراقبة الشبكة وتحليل حركة البيانات على ويندوز، بواجهة عربية
Network monitoring & traffic analysis for Windows

Release Platform Electron React TypeScript Tests License

العربية · English


العربية

blazma.nt يراقب شبكتك (أو أي شبكة عندك تصريح تراقبها) ويوريك وش يصير فيها فعلًا: مين الأجهزة المتصلة، ووين تتصل، ووش البروتوكولات اللي تستخدمها، وأي جزء من الحركة يمشي بدون تشفير. المراقبة سلبية وللقراءة فقط، والبرنامج يقدر كمان يتحكم بالراوتر حقك عن طريق واجهة الراوتر الرسمية، بدون أي تلاعب أو حقن أو قطع للشبكة.

الواجهة عربية من اليمين لليسار افتراضيًا، وتقدر تحوّلها للإنجليزي من الإعدادات. فيه وضع داكن ووضع فاتح.

لوحة المعلومات

⬇️ التحميل

حمّل آخر نسخة من صفحة الإصدارات وشغّل blazma.nt-Setup-<الإصدار>.exe.

ويندوز ممكن يطلع لك تحذير SmartScreen لأن المثبّت غير موقّع رقميًا. اضغط «More info» ثم «Run anyway».

✨ المميزات

📊 لوحة المعلومات رسم مباشر للحركة، وأكثر الأجهزة استهلاكًا، وأكثر البروتوكولات، وعدد الأجهزة والاتصالات
🖥️ اكتشاف الأجهزة كل جهاز على الشبكة: IP وMAC والشركة المصنّعة (بدون نت)، وأول وآخر ظهور، والرفع والتنزيل
⇄ الحركة المباشرة جدول لحظي للاتصالات فيه البروتوكول والاتجاه والتشفير والحجم، والواجهة ما تعلّق
⋈ الاتصالات سجل اتصالات تقدر تبحث فيه وتفلتره، مع حالة TCP وحجم كل اتصال
◈ تحليل البروتوكولات يتعرّف على البروتوكول من محتوى الحزمة نفسها مو من رقم المنفذ: DNS وHTTP وTLS وDHCP وQUIC وSSH وغيرها
🔒 HTTPS / TLS اسم الموقع والإصدار وأسماء الشهادة، من الأشياء اللي TLS يرسلها مكشوفة بس، وبدون فك تشفير أبدًا
⚠️ الحركة غير المشفّرة ينبّهك على البروتوكولات المكشوفة ويعرض بيانات وصفية غير حساسة، وأي كلمة سر أو كوكيز تنحذف تلقائيًا
⌖ مراقبة DNS سجل الاستعلامات والردود، مع زر يمسحها كلها لخصوصيتك
◉ التنبيهات جهاز جديد، بروتوكول غير مشفّر، ارتفاع مفاجئ في الحركة، نمط فحص منافذ... وكل تنبيه يقول لك السبب، بدون ما يتهم أحد
◱ التحليلات سرعة النت والذروة والنسب وتقارير لآخر ساعة / يوم / أسبوع / شهر، وتصدير CSV / JSON / PDF
⌂ التحكم بالراوتر احظر أي جهاز أو فك حظره، وغيّر DNS، وأعد تشغيل الراوتر، عن طريق واجهة الراوتر الرسمية
⏺ التقاط الحزم تسجيل PCAP بس لما تطلبه أنت، وبحد للمدة والحجم. ما يتسجّل شي تلقائيًا

التحكم بالراوتر
التحكم بالراوتر: أوامر ترسل مباشرة لراوترك، بدون انتحال ولا حقن.

الإعدادات
البرنامج يكتشف طريقة الالتقاط لحاله: Npcap مع dumpcap إذا موجودين، وإلا pktmon المدمج في ويندوز.

الصور مأخوذة من واجهة البرنامج ببيانات تجريبية.

🚫 وش ما يسويه البرنامج

هذي قيود مقصودة في التصميم، مو ميزات ناقصة:

  • ما يفك التشفير. حركة HTTPS/TLS ما تنفك ولا تنعترض أبدًا. يعرض بس اللي TLS يرسله مكشوف (اسم الموقع، والإصدار، وأسماء الشهادة إذا ظهرت).
  • ما يجمع كلمات سر. كلمات السر والكوكيز ومعرّفات الجلسات وترويسات التفويض ومفاتيح API ما تنجمع أبدًا. محلّل HTTP يحتفظ بس بالترويسات اللي في قائمة مسموحة، والباقي ينحذف قبل ما يتسجّل.
  • ما فيه ARP spoofing ولا MITM ولا تحويل DNS. البرنامج ما يرسل شي على الشبكة أصلًا، فما يقدر يقطعها أو يحوّل حركتها.
  • ما فيه تتبع ولا سحابة. ولا شي يطلع من جهازك. حتى معرفة الشركة المصنّعة من عنوان MAC تصير من جدول داخل البرنامج، عشان عناوين أجهزتك ما تروح لأي طرف ثاني.

راقب بس الشبكات اللي تملكها أو عندك إذن تراقبها.

🧰 المتطلبات

المتطلب ملاحظات
ويندوز 10 (1809 أو أحدث) أو ويندوز 11 64 بت
Npcap لالتقاط الحزم مباشرة (اختياري، شوف تحت)
Wireshark يوفّر dumpcap.exe اللي يلتقط الحزم
Node.js 20 أو أحدث للتطوير بس

تثبيت Npcap

  1. حمّل المثبّت من https://npcap.com/#download.
  2. شغّله كمسؤول (Administrator).
  3. فعّل خيار «Install Npcap in WinPcap API-compatible Mode».
  4. خلّ خيار «Restrict Npcap driver's access to Administrators only» بدون تفعيل، إذا تبغى تلتقط بدون ما تشغّل البرنامج كمسؤول.
  5. أعد تشغيل blazma.nt. تقدر تشوف الحالة من الإعدادات ← الالتقاط.

طرق الالتقاط

البرنامج يختار أفضل طريقة متوفرة لحاله:

  1. Npcap مع dumpcap (الأفضل). بث مباشر بأقل تأخير. dumpcap أداة الالتقاط اللي تجي مع Wireshark، وكل التحليل يصير داخل blazma.nt.
  2. pktmon (البديل المدمج). موجود في ويندوز أصلًا، فما تحتاج تثبّت شي. بس لازم تشغّل البرنامج كمسؤول، والحركة توصل على دفعات كل كم ثانية بدل ما تكون لحظية. تقدر تجرّبه بـ node scripts/test-pktmon.mjs (كمسؤول).

ليش Npcap مو مضمّن مع البرنامج؟ رخصة Npcap تمنع توزيعه داخل برامج ثانية بدون رخصة تجارية، ومثبّته المجاني ما يشتغل بصمت. عشان كذا البرنامج يشتغل مباشرة عن طريق pktmon، ويستخدم Npcap تلقائيًا إذا ثبّته بنفسك.

إذا ما فيه أي طريقة التقاط متوفرة، البرنامج يشتغل عادي ويقول لك بالضبط وش الناقص وليش، بدل ما يعرض شاشات فاضية.

🔐 الخصوصية والأمان

  • وضع الخصوصية (الإعدادات ← الخصوصية): يوقف تسجيل أي شي مأخوذ من محتوى الحزم، يعني استعلامات DNS وبيانات HTTP وأسماء مواقع TLS، والأجهزة والاتصالات والعدّادات تظل تشتغل. وتقدر تمسح سجل DNS أي وقت، وتوقف تخزين DNS أو البيانات غير المشفّرة كل واحد لحاله.
  • الحزم الخام ما تتخزّن. قاعدة البيانات فيها بيانات وصفية وإحصائيات بس. الحزم توصل للقرص فقط إذا بدأت التقاط PCAP بنفسك.
  • مدة الاحتفاظ بالبيانات تختارها أنت (يوم / أسبوع / شهر / 3 شهور / بدون حد)، وتقدر تمسح أي نوع بيانات يدويًا من الإعدادات.
  • الواجهة معزولة عن النظام (contextIsolation) ومالها وصول للنت، وتتكلم مع البرنامج من قنوات محددة بس.
  • ما فيه أوامر shell. البرامج الخارجية تشتغل بدون cmd.exe، وكل المدخلات (الواجهة، فلتر الالتقاط، مسار الحفظ) تتفحص قبل الاستخدام.
  • صلاحيات أقل. البرنامج ما يطلب صلاحيات مسؤول إلا إذا احتاجها الالتقاط.

🛠️ حل المشاكل

«Npcap مطلوب لمراقبة حركة الشبكة» Npcap مو مثبّت، أو مثبّت بدون وضع WinPcap API-compatible. ثبّته من جديد من npcap.com مع تفعيل الخيار، وأعد تشغيل البرنامج.

«لم يُعثر على dumpcap.exe» ثبّت Wireshark. البرنامج يدوّر عليه في C:\Program Files\Wireshark وC:\Program Files (x86)\Wireshark و%LOCALAPPDATA%\Programs\Wireshark.

كرت الشبكة مكتوب جنبه «no capture device» الكرت ماله مقبض التقاط من Npcap، غالبًا لأن Npcap مو مثبّت أو لأن الكرت افتراضي. الكروت اللي ينفع الالتقاط منها تطلع أول القائمة ومكتوب عليها capturable.

الالتقاط يبدأ ويوقف على طول غالبًا Npcap مثبّت مع خيار «restrict to Administrators». يا تثبّته من جديد بدون الخيار، يا تشغّل البرنامج كمسؤول.

أجهزة مكتوب عليها «Randomized MAC» الجوالات الحديثة تغيّر عنوان MAC لكل شبكة، فما ينفع نعرف الشركة المصنّعة منه، والبرنامج يقول لك هذا بدل ما يخمّن.

حزم تضيع (يطلع العدد فوق) خفّف معدّل تحديث الواجهة من الإعدادات ← الأداء، أو حط فلتر التقاط يقلّل الحركة.

👨‍💻 للمطوّرين

npm install
npm run dev      # تشغيل للتطوير
npm test         # الاختبارات
npm run dist     # بناء المثبّت release/blazma.nt-Setup-<الإصدار>.exe

الاختبارات تبني حزمها من ملفات تجريبية في tests/fixtures.ts، وما تلمس أي شبكة حقيقية. شرح البنية وهيكل المشروع بالتفصيل في القسم الإنجليزي تحت.

📄 الرخصة

MIT. خط IBM Plex Sans Arabic المضمّن برخصة SIL Open Font License 1.1 (src/renderer/src/fonts/OFL.txt).


English

blazma.nt watches a network you own — or are authorised to monitor — and shows you what is actually on the wire: which devices are connected, what they talk to, which protocols they use, and which of that traffic is travelling unencrypted. It is strictly passive and read-only for monitoring, and adds active control of your own router through the router's official API — no spoofing, no packet injection, no network disruption.

Arabic (RTL) is the default interface language; English can be chosen in Settings. Dark and light themes.


Features

📊 Dashboard Live traffic graph, top talkers, top protocols, device & connection counts
🖥️ Device discovery Every device on the LAN — IP, MAC, vendor (offline OUI), first/last seen, up/down
⇄ Live traffic Real-time flow table with protocol, direction, encryption, size — never freezes the UI
⋈ Connections Searchable, filterable flow history with TCP state and per-flow byte counts
◈ Protocol analysis Header-based identification (not port guessing) for DNS, HTTP, TLS, DHCP, QUIC, SSH…
🔒 HTTPS / TLS SNI, version and certificate names read only from what TLS sends in the clear — never decrypted
⚠️ Unencrypted traffic Flags cleartext protocols; shows non-sensitive metadata with credentials redacted by allowlist
⌖ DNS monitor Query/response log with a one-click privacy purge
◉ Alerts New device, unencrypted protocol, traffic spike, port-scan pattern… each with a stated reason, never a verdict
◱ Analytics Bandwidth, peaks, ratios and reports over 1h / 24h / 7d / 30d, exportable to CSV / JSON / PDF
⌂ Router control Block/unblock any device, change DNS, reboot — via your router's own API
⏺ Packet capture Explicit, opt-in PCAP recording with duration/size caps — nothing is recorded automatically

blazma.nt in English, light theme
The English interface in the light theme. Router Control and Settings are shown in the Arabic section above.


What it will not do

These are design constraints, not missing features:

  • No decryption. HTTPS/TLS traffic is never decrypted or intercepted. Only what TLS sends in the clear (SNI, negotiated version, and certificate names when the handshake exposes them) is displayed.
  • No credentials. Passwords, cookies, session identifiers, authorisation headers and API keys are never collected. In the HTTP parser this is enforced by an allowlist: unlisted headers are dropped before the record is built, so there is no code path where a secret is captured and filtered afterwards.
  • No ARP spoofing, MITM or DNS hijacking. blazma.nt never transmits on the network. It cannot disrupt or redirect traffic because it has no write path.
  • No telemetry, no cloud. Nothing leaves the machine. Vendor lookup for MAC addresses is an offline table, precisely so that your device addresses are not sent to a third party.

Only monitor networks you own or have permission to monitor.


Requirements

Requirement Notes
Windows 10 (1809+) or Windows 11 x64
Npcap Required for packet capture
Wireshark Provides dumpcap.exe, the capture helper
Node.js 20+ Development only

Installing Npcap

  1. Download the installer from https://npcap.com/#download.
  2. Run it as Administrator.
  3. Enable "Install Npcap in WinPcap API-compatible Mode".
  4. Leave "Restrict Npcap driver's access to Administrators only" unchecked if you want to capture without running blazma.nt elevated.
  5. Restart blazma.nt. Settings → Capture shows the detected state.

Capture backends

blazma.nt picks the best available capture path automatically:

  1. Npcap + dumpcap (preferred). A true live stream with the lowest latency. dumpcap — the capture-only tool bundled with Wireshark — performs no dissection; it hands over raw frames and every byte of analysis happens inside blazma.nt. Needs no native compilation.
  2. pktmon (built-in fallback). Windows ships pktmon, so this path needs nothing installed — it works the moment blazma.nt is installed. It requires running blazma.nt as Administrator, and captures in short segments (a few seconds of latency rather than instant), because pktmon is file-based rather than a live stream. Verify it with node scripts/test-pktmon.mjs (as Administrator).

Why Npcap is not bundled. Npcap's licence prohibits redistribution inside other software without a commercial OEM licence, and its free installer cannot run silently. blazma.nt therefore never ships or auto-installs Npcap — instead it works out of the box via pktmon, and uses Npcap automatically if you have installed it yourself.

If no backend is available, the app still runs and tells you exactly what is missing and why; it does not silently show empty screens.


Running

npm install
npm run dev

Production build:

npm run build
npm start

Windows installer (release/blazma.nt-Setup-<version>.exe):

npm run dist

Tests:

npm test

The suite builds its own packets from fixtures in tests/fixtures.ts; it never touches a real network and contains no captured traffic.


Architecture

Npcap driver
    │
    ▼
dumpcap -P -w -            classic pcap on stdout
    │
    ▼
PcapStreamReader           reassembles records across pipe chunks
    │
    ▼
parsePacket()              Ethernet/VLAN → IPv4/IPv6/ARP → TCP/UDP/ICMP
    │                      → DNS · HTTP · TLS · DHCP · QUIC · NTP …
    ▼
Engine  ── FlowTracker      bidirectional 5-tuple table, TCP state machine
        ── DeviceRegistry   MAC/IP identity, offline OUI vendor lookup
        ── AlertEngine      threshold rules with stated reasons
        │
        │  aggregates once per second, publishes at uiUpdateHz
        ▼
    SQLite (node:sqlite)  +  EventBus
                                │
                                ▼
                        preload bridge (allowlisted channels only)
                                │
                                ▼
                        React + Tailwind + Recharts

The rule that makes this scale: the UI never receives a packet. The engine folds packets into in-memory tables, flushes aggregates to SQLite once per second, and pushes batched summaries to the renderer a couple of times per second. Packet rate therefore affects backend CPU, not UI responsiveness.

Project layout

src/
  main/        Electron main process, window lifecycle, IPC handlers
  preload/     The only renderer↔backend bridge (channel allowlist)
  shared/      Types and the IPC contract used by both sides
  backend/
    capture/   Environment probing, dumpcap source, pcap reader, PCAP jobs
    parser/    Pure packet parsers (ethernet, ip, tcp/udp, dns, http, tls, dhcp)
    flows/     Flow tracker and TCP state machine
    devices/   Device registry, interface enumeration, OUI vendors
    alerts/    Threshold rules
    analytics/ Ranges, reports, CSV/JSON/PDF export
    database/  Driver, migrations, repositories
    security/  Input validation
    core/      Event bus, settings, the engine that ties it together
    utils/     Net maths, formatting, logging, PDF writer
  renderer/    React UI (pages, components, i18n)
tests/         Vitest suites over fixtures
build/         Installer customisation

Storage

SQLite via Node's built-in node:sqlite (Electron 43 ships Node 24), with node-sqlite3-wasm as an automatic fallback. Either way there is no native module to compile.

Raw packets are never stored. The database holds metadata and aggregates only: devices, flows, protocol counters, DNS records, redacted HTTP metadata, TLS handshake facts, alerts and logs. Packets reach the disk only through an explicit PCAP capture that you start yourself.

Retention is configurable (1 / 7 / 30 / 90 days or unlimited) and enforced at startup and every 15 minutes. Any category can be deleted manually from Settings.


Security

  • Renderer sandboxing. contextIsolation: true, nodeIntegration: false. The renderer is a plain web page with a strict CSP and no network access.
  • IPC allowlist. The preload bridge exposes a fixed list of channels in both directions. There is no generic "invoke any channel" escape hatch.
  • No shell. Child processes are spawned with argv arrays and shell: false. No string is ever handed to cmd.exe, so there is no command-injection surface.
  • Validated inputs. Interface ids must match the Npcap device pattern; BPF filters are checked against a keyword allowlist and cannot begin with -, so extra options cannot be smuggled into the capture tool; output paths must be absolute with an allowed extension.
  • Parameterised SQL. Every caller-supplied value is a bound parameter. Sort columns come from a fixed set, never from the request.
  • Scrubbed logs. The logger strips credential-shaped text as a second line of defence.
  • Least privilege. The app requests asInvoker. Elevation is only needed for capture if Npcap was installed with the Administrators-only restriction.

Privacy

Privacy Mode (Settings → Privacy) stops recording anything derived from packet payloads — DNS queries, HTTP metadata and TLS server names — while devices, flows and byte counters keep working. DNS history can be deleted at any time, and storage of DNS and unencrypted metadata can each be switched off independently.


Troubleshooting

"Npcap is required to monitor network traffic." Npcap is not installed, or was installed without WinPcap API-compatible mode. Reinstall it from npcap.com with that option enabled and restart the app.

"dumpcap.exe was not found." Install Wireshark. blazma.nt looks in C:\Program Files\Wireshark, C:\Program Files (x86)\Wireshark and %LOCALAPPDATA%\Programs\Wireshark.

The interface list shows "no capture device". That adapter has no Npcap capture handle — usually because Npcap is missing, or because the adapter is virtual. Adapters that can be captured are listed first and marked capturable.

Capture starts, then stops immediately. Npcap was probably installed with "restrict to Administrators". Either reinstall without that option, or run blazma.nt as Administrator.

Devices appear with a "Randomized MAC" vendor. Modern phones randomise their MAC per network. The address is locally administered, so no vendor can be derived from it — the app says so instead of guessing.

Packets are being dropped (shown in the header). Lower the UI update rate in Settings → Performance, or apply a capture filter to reduce the volume reaching the parser.


Licence

MIT. The bundled IBM Plex Sans Arabic font is under the SIL Open Font License 1.1 (src/renderer/src/fonts/OFL.txt).

About

Passive network monitoring & traffic analysis for Windows, with active control of your own Huawei router (block devices, DNS, reboot). Electron + React + TypeScript. Privacy-first.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages