I2P Operators
Monitor the local router, address book activity, listeners, persistent peers, tunnel-adjacent services, and recurring connection patterns.
A focused desktop utility for observing, classifying, filtering, documenting, and managing I2P-related network connections without turning the operator’s desktop into a packet-analysis laboratory.
I2PMon X is a professional desktop utility designed to transform raw operating-system connection information into a structured operational view of an I2P environment. It watches network activity associated with the I2P stack, records peer behavior, identifies processes and ports, tracks connection history, supports manual peer actions, and produces comprehensive JSON exports suitable for documentation, troubleshooting, research, or later analysis.
The application is intentionally narrower than a packet analyzer and more informative than a simple connection list. It does not attempt to decrypt traffic, inspect packet payloads, or interfere with tunnel construction. Its value lies in making observable facts easier to interpret: which process owns a connection, when it appeared, how long it remained active, which ports were used, whether the peer returned, what classification applies, and what policy the operator assigned.
I2PMon X is built for users who need practical visibility into anonymous networking without abandoning the privacy principles that make I2P useful.
Monitor the local router, address book activity, listeners, persistent peers, tunnel-adjacent services, and recurring connection patterns.
See what is active around a privacy-focused workstation without relying on vague assumptions or oversized enterprise dashboards.
Document process-linked connections, evaluate repeated behavior, isolate unknown activity, and export evidence in structured JSON.
Track listeners, identify owning processes, inspect peer histories, add notes, and distinguish expected services from unexplained activity.
Observe application behavior while developing I2P-aware software, testing tunnel configurations, or validating service deployment.
Use a readable visual interface to study TCP states, listeners, local services, processes, anonymous networking, and connection lifecycles.
Start, stop, and manually trigger connection scans with a configurable interval.
View protocol, endpoints, state, PID, process, classification, action, lifetime, and recurrence.
Filter by free text, process, state, class, action, port, address, or other visible connection fields.
Inspect first seen, last seen, hit counts, observed ports, observed states, notes, and policy status.
Export configuration, runtime state, peers, policies, blocklist, connections, history, statistics, and events in one JSON file.
Choose the interface that works for the room, display, time of day, and operator preference.
Begins continuous monitoring. I2PMon scans at the configured interval and updates connection, peer, history, and statistics data.
Stops automatic scanning while preserving the records already collected during the current run.
Runs an immediate one-time scan. This is useful when validating a service change, checking a newly started process, or refreshing the display without enabling continuous monitoring.
Controls how many seconds pass between automatic scans. Short intervals provide more immediate visibility. Longer intervals reduce repeated system queries and disk writes.
The application reports whether monitoring is active, stopped, waiting, or completing a scan. The statistics area summarizes active connections, listeners, established sessions, unique peers, blocked peers, redirected peers, and logged events.
Restricts the visible and recorded connection list to activity that matches known I2P ports, processes, or relevant behaviors.
Controls whether discovered connection events are automatically written to the event log.
Allows the application to terminate a matching locally owned process when a blocked connection can be tied to a PID. This option should be used carefully because terminating a process can affect more than one connection.
Switches between Light and Dark themes. The selected theme is stored in the configuration and restored when the application launches again.
Assigns one of the available policies to the selected peer: Observe, Redirect, or Block.
Filter the connection table by state, process, classification, or action. These controls can be combined with the text filter to narrow the display quickly.
The main table presents connection information in sortable columns. Depending on the current build, available fields may include:
Clicking a column heading sorts the current records by that field.
The text filter searches across visible connection information. Typical searches include:
The dropdown filters may be used independently or combined with the text filter. Clear restores the unfiltered view.
The default policy. The peer remains visible and continues to accumulate history without intervention.
Marks the peer for alternate handling in the application’s policy records. Redirect is a management label and does not silently reroute or hijack traffic.
Adds the peer address to the persistent blocklist. When Kill Blocked is disabled, the policy remains informational. When enabled and a PID is available, the application may attempt to terminate the owning process.
Each observed peer accumulates a persistent history including first seen, last seen, hit count, observed states, ports, policy, blocked status, notes, and resolved host name when available.
Where supported, the operator can request a reverse DNS lookup for a selected address. Manual resolution avoids slowing every scan and prevents unnecessary DNS traffic.
Notes allow documentation of known peers, research findings, normal behavior, follow-up tasks, or reasons for a block or redirect policy.
The complete export captures application metadata, configuration, theme, monitoring options, runtime state, statistics, peers, peer history, notes, resolved names, policies, blocklist, current connections, lifetime data, reconnect information, and historical event records.
The resulting JSON can be archived, searched, compared between sessions, processed with scripts, imported into analytical tools, or retained as part of an incident or research record.
Dark mode is designed for low-light operational environments and long monitoring sessions. Light mode improves readability in daylight, bright rooms, and high-glare displays. Theme switching does not affect monitoring or saved data.
The application is an operational connection monitor and management aid, not a complete firewall, intrusion-detection platform, or forensic packet-analysis suite. Classifications are based on observable host information such as ports, processes, connection states, and known I2P patterns.
I2PMon X is provided as an informational, educational, administrative, and research utility. Network information may be incomplete, delayed, misclassified, altered by operating-system permissions, or affected by differences in system tools and platform behavior. Operators should verify important findings with appropriate system utilities and professional judgment.
The application does not guarantee security, anonymity, privacy, threat prevention, connection blocking, or uninterrupted operation. Use of I2PMon does not replace secure configuration, operating-system updates, firewall management, access controls, logging policy, or incident-response procedures.
Use I2PMon only on systems and networks you own, administer, or are explicitly authorized to inspect. The operator is responsible for complying with applicable laws, organizational policies, privacy obligations, and network-use agreements.
Unless a separate license file accompanies the distributed package, the software remains the intellectual property of its author and is provided for personal, educational, administrative, and authorized research use. Redistribution, modification, commercial packaging, or representation as another party’s work requires the author’s permission.
The software is provided “as is,” without warranties of merchantability, fitness for a particular purpose, security, accuracy, or non-infringement. The author is not responsible for data loss, service interruption, process termination, blocked connections, misinterpretation of network information, or other damages arising from use of the application.