RECONIFIED is a single-host Windows EDR/XDR console, designed so that every process, file, port and privileged action it uses can be inspected by you or a third-party auditor.


Win32, ETW and documented Windows APIs. No minifilter, ELAM, PPL or kernel callback.

Each privileged action needs a matching operator grant and its own Windows UAC prompt.

Telemetry, alerts and cases stay in SQLite under ProgramData. Egress only goes where you point it.

Grant, policy, containment and quarantine changes are chained with SHA-256, so edits and gaps show up.
Tauri 2 and WebView2 render the console. Rust owns sensors, storage and actions. The UI talks to the agent over Tauri commands, not a web API.
None of these checks need the vendor. Run them on any host with RECONIFIED and compare the results with this page.
Confirm neither appears in the process tree or in sc.exe. Only reconified-app.exe runs, at medium integrity.
Read operator-grants.json and compare it with the sign-in task, the ETW session and the firewall rule list.
Call /v1/health with no key and with the published development string. Both must return 401.
The read-only REST port 9477 and the SSO redirect port 9478 bind to 127.0.0.1 and nothing else.
local-api-key, local-policy-key and idp.json are readable only by SYSTEM, Administrators and the current user.
Run the verifier against tier1.db and record head_hash somewhere outside the host.
Send a command outside the allowlist and confirm it is refused.
Firewall, terminate and ETW session creation fail from reconified-app.exe alone. A denied UAC prompt leaves the action failed.
If RECONIFIED\Background exists on an unpackaged install, its run level is LIMITED, not HIGHEST.
Straight answers about what RECONIFIED does and does not do on a Windows PC.