Overview
The AI option provides a behavioural analysis of the selected application and its network connection.
The purpose is to help users understand unexpected communication and make informed decisions about possible containment actions.
AI analysis does not decide whether an application is safe or unsafe. The final decision always remains with the user.
Application + Network Context
AI analysis evaluates the combination of:
| Item | Meaning |
|---|---|
| Application | The local program responsible for creating the connection. |
| Network | The remote destination used by that application. |
| Behaviour | How the communication pattern compares with expected application behaviour. |
A network itself is not automatically unusual. The same network may be normal for one application and unexpected for another application.
For example, a browser or updater normally communicates with external servers. A program that normally works locally but maintains continuous background connections may require closer review.
Using AI Analysis
| User Action | Result |
|---|---|
| Press AI Button | Enables AI analysis mode. |
| Hover over Network name | The network name changes to blue, indicating that analysis is available. |
| Click blue Network name | The network name changes to green and the analysis request is sent. |
| AI completes analysis | The result is displayed in the existing Information / Actions panel. |
AI Analysis Scope
AI analysis evaluates only:
- The selected application.
- The selected network connection.
- The available information related to this connection.
AI does not analyse other applications, previous sessions, other computers, or complete network environments.
AI Result Information
| Result | Description |
|---|---|
| Behaviour Score | A value from 0–100 indicating how unusual the observed behaviour appears. |
| Risk Category | Classification such as Expected, Background, Unusual, Suspicious, or Highly Anomalous. |
| Summary | Short explanation of the analysis result. |
| Main Reasons | Important factors influencing the assessment. |
| Recommended Action | Suggested containment action based on the observed behaviour. |
| Blocking Impact | Explanation of what communication will be affected. |
Understanding the Score
A higher score means the observed behaviour is less typical. It does not automatically mean the application is unsafe.
Always consider:
- Why the application is installed.
- Whether the application was started intentionally.
- Whether network communication is expected.
User Control and Safe Testing
AI provides guidance, but the user decides whether to apply a containment action.
Stopping or blocking communication can be tested and reversed. If a required function is affected, communication can be restored.
Managing Blocked Network Rules
WhoIsConnected does not store a separate copy of blocked connections.
The current Windows Firewall configuration is retrieved directly whenever blocked rules are requested.
To review blocked rules:
- Open the menu button (☰) in the top-right corner.
- Select Get Blocked Networks List.
- Review the current Windows Firewall rules.
- Restore communication using the available unblock actions.
| Control | Description |
|---|---|
| Application | Rules related to a specific program. |
| Network | Rules related to a remote destination. |
| Direction | Restore incoming, outgoing, or both directions. |
Important: IP vs Network Blocking
Blocking one IP affects only one destination.
Blocking a network range affects a wider group of related addresses.
Always review the application and connection context before applying broader network blocking.
⚠ AI Limitations
AI analysis is based only on the information available for the selected application and connection.
The user remains responsible for deciding whether a connection should be allowed, stopped, or blocked.