Skip to content

Repository files navigation

WireFox

WireFox Logo
Automated Roaming & Watchdog Manager for WireGuard on Windows
The WireGuard companion fox you didn't think you'd need.
Crafted with care by FoxDen Software

License: PolyForm Perimeter 1.0.0 .NET 10.0 Windows 10 / 11 WinGet Package GitHub Downloads


⚡ The Missing Piece of WireGuard on Windows

On mobile devices (iOS / Android), WireGuard has native on-demand rules: your phone automatically connects to VPN when you leave your house, and turns off when you're connected to home Wi-Fi.

On Windows, however, laptops have historically lacked intelligent roaming. Users were left with only two choices: manually clicking connect every time they leave the house, or hacking together fragile Task Scheduler scripts.

WireFox bridges that gap. It is a lightweight, modern background assistant and system tray daemon for Windows that automates your WireGuard tunnel based on your current network environment.


✨ Features

  • 🔄 Intelligent Network Roaming
    • Auto-Bypass on Trusted Wi-Fi: Disconnects VPN when connected to your home or office Wi-Fi for full gigabit LAN speeds.
    • Auto-Connect on Untrusted Networks: Automatically spins up the WireGuard tunnel the moment you connect to an open or untrusted network (coffee shops, hotels, airports).
  • 🛡️ Gateway MAC (ARP) Anti-Spoofing
    • Identifies trusted networks not just by SSID name, but by default gateway MAC address (iphlpapi.dll SendARP).
    • Protects Ethernet connections and guards against rogue Wi-Fi access points spoofing your home SSID.
  • 🐕 Handshake & Session Watchdog
    • Actively polls kernel handshake timestamps via the official wg.exe command layer.
    • Detects silent UDP drops, captive portals, and dead tunnels.
    • Built-in timer controls: pause protection for 15 minutes or temporarily switch to split-tunnel mode.
  • 💻 Native Windows Experience
    • Built with modern WPF and clean Windows 10/11 dark/light themes.
    • Sits quietly in the Windows System Tray with quick controls.
    • Native Windows Toast notifications with actionable inline buttons.
    • Starts silently on Windows boot via elevated Scheduled Task without annoying UAC prompts.
  • 🔒 Zero Bloat, Zero Telemetry
    • No accounts, no background analytics, no ads.
    • Interacts directly with the official, audited WireGuardNT service driver.

🚀 Quick Start & Installation

Requirements

  • Windows 10 (version 19041+) or Windows 11
  • Official WireGuard for Windows installed (wireguard.com/install)

🪟 Windows Package Manager (WinGet)

winget install FoxDenSoftware.WireFox

⚡ One-Line Install (PowerShell)

Run the following in PowerShell (Administrator recommended):

irm https://raw.githubusercontent.com/TalviFox/WireFox/main/install.ps1 | iex

This automatically fetches the latest release, installs WireFox to Program Files, and adds a Start Menu shortcut.

📦 Manual Download

  1. Download the latest WireFox.exe from Releases.
  2. Launch WireFox.exe as Administrator (required to manage Windows tunnel services).
  3. Select your tunnel in Settings (or import a .conf file).
  4. Add your home Wi-Fi or router to Trusted Networks.

🔒 Verify Binary Integrity (SHA-256)

WireFox is open-source and independent. You can audit the integrity of your binary directly against GitHub Releases at any time without commercial code-signing:

irm https://raw.githubusercontent.com/TalviFox/WireFox/main/verify.ps1 | iex

🧹 Clean Uninstall

WireFox can be removed natively from Windows Settings > Installed Apps, directly inside WireFox under Settings > Clean System Removal, or via PowerShell:

irm https://raw.githubusercontent.com/TalviFox/WireFox/main/uninstall.ps1 | iex

📝 Changelog

  • Graceful SCM Tunnel Teardowns: Extended SCM stop timeout to 8s with StopPending state handling, allowing Windows NDIS and Wintun driver to unbind cleanly without false timeouts.
  • Service Deletion Guard: Eliminated premature sc.exe delete calls on healthy stops, preventing Win32 Error 1072 (ERROR_SERVICE_MARKED_FOR_DELETE) and enabling instant (<1s) starts via existing service reuse.
  • Trusted Settle Optimization: Guarded OnNetworkSettled to prevent redundant teardowns, taskkill calls, and DNS cache flushing while sitting on trusted networks.
  • Stale Tunnel Outage/Sleep Recovery: Automatically detects and gracefully refreshes tunnels with stale handshakes when reconnecting after extended network outages or sleep.
  • Non-Destructive Watchdog Recovery: Refactored ForceRestartTunnelAsync() to attempt a gentle restart first before escalating to full reset.
  • Strict WireGuard Scope Enforcement: Enforced strict WireGuard naming specification and Windows NT service backing during discovery, eliminating phantom tunnel detections from NDIS filter miniports, packet capture bindings (Npcap/WinPcap), and virtual bridges.
  • UI & UX Polish: Added text wrapping and hover tooltips for long tunnel names, toast feedback for manual diagnostic scans, bold category labels on the Status page, and side-scrolling for log console entries.
  • Fix: Replaced native wireguard.exe tunnel uninstallation with silent sc.exe delete to eliminate "Service does not exist" Error UI popups when disconnecting/trusting networks.
  • Fix: Overhauled gateway storage logic to uniquely identify trusted networks by IP + MAC Address, resolving a major bug where multiple networks sharing the same default gateway (e.g. 192.168.1.1) would overwrite each other and trigger false-positive anti-spoofing lockouts.
  • Resilient Tunnel Deactivation & Zombie Prevention: Resolved the WireGuard deactivation freeze where driver deadlocks left services spinning in StopPending state. Added graceful stop timeout (3s) with immediate escalation to hosting process termination, SCM driver unbinding, and active DNS cache resolver flushing (DnsFlushResolverCache) to prevent Windows Filtering Platform (WFP) kernel blackholes.
  • Interactive Tray Control: Added direct Kill WireGuard (Force Stop) action item to the system tray.
  • Differential Watchdog Diagnostics: Integrated Layer-2 default gateway ARP probing (ArpService) and ICMP verification to validate physical network reachability before attributing connection loss to WireGuard, eliminating false-positive restarts when physical connectivity is lost.
  • Active End-to-End Connectivity Probing: Handshake watchdog actively tests HTTP 204 endpoints (generate_204) with fallback DNS resolution checks against msftconnecttest.com to detect silent UDP drops and dead routes.
  • Intelligent Toast Notification Debouncing: Replaced rapid notification spam during network transitions with in-place Windows toast replacements (tagged wirefox group) and strict cooldown timers (10m for network discovery, 3m for watchdog alerts).
  • Encoding & Script Hardening: Fixed PowerShell emoji mojibake across install.ps1, uninstall.ps1, verify.ps1, and release.ps1 by moving to runtime surrogate generation, XML entity escaping, and enforcing UTF-8 without BOM across all build pipelines.
  • Re-tooled Installer Logic: Updated install options and double click behavior as well as script theming.

For older releases, see GitHub Releases.


🛠️ Building from Source

WireFox is built on .NET 10.0 Windows Desktop SDK.

# Clone the repository
git clone https://github.com/TalviFox/WireFox.git
cd WireFox

# Build single-file release executable
dotnet publish WireFox.csproj -c Release -r win-x64 --self-contained true -p:PublishSingleFile=true -o publish/

Or run build.bat in the root directory.


🤖 Transparency & AI Disclosure

WireFox is developed with the assistance of AI coding tools. In the spirit of open development and personal accountability: I don't post what I don't run.

Every feature, script, and build is actively dogfooded, tested, and run on my own daily-driver machines before it is published here.


⚖️ License

WireFox source code is available under the PolyForm Perimeter License 1.0.0.

What this means:

  • ✅ Open to inspect, fork, and hack: You are free to run, study, modify, build, and distribute WireFox for personal, educational, or internal use.
  • 🛡️ Anti-theft & non-compete protection: You may not use this software or its source code to provide or market any product or service that competes with WireFox or acts as a commercial substitute for it.

For full license terms, see the LICENSE file or visit PolyForm Project.


🏷️ Trademarks & Attribution

  • WireGuard® is a registered trademark of Jason A. Donenfeld.
  • WireFox is an independent companion project developed by FoxDen Software. It is not affiliated with, endorsed by, or sponsored by Jason A. Donenfeld or the official WireGuard development team.

🛡️ Early Access & Security Notice

WireFox is independent, early-access utility software provided on an "AS IS" and "AS AVAILABLE" basis, without warranties of any kind, express or implied. While WireFox is actively maintained, dogfooded daily, and designed to automate and protect WireGuard connections, local network environments (such as captive portals, hotel Wi-Fi, and adapter driver states) can vary widely. Users are solely responsible for ensuring their network environment and personal data security requirements are satisfied.

About

Automated WireGuard Roaming Assistant

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages