Security
Built to be checked, not just trusted
CommMonitor is installed next to software you cannot afford to disturb. This page describes what it changes on a machine and how you can verify it yourself.
Executable
Native x64 machine code
The 2026H1 build is written in Delphi 12 Athens for Win64 and compiles straight to native code.
- No .NET, Java or other managed runtime is installed or required.
- There is no intermediate language, so there is no IL assembly to decompile back into readable source.
- The application is a single executable plus the bundled driver; the licence is verified locally, with the public key compiled into the product.
Kernel driver
A filter, not a port owner
Capture happens in a small kernel driver that attaches a filter to the serial device stack.
- Your application keeps the COM port handle; the filter only observes the requests that pass through it.
- The driver runs as the service CommMonitorDrv12x and is reached through the device path \\.\ComDrv12x.
- Installation is install-only by design: stopping a filter driver that already sits in a device stack can leave the device in an undefined state, so no uninstall action is offered.
- Installing or starting the driver needs administrator rights. Capturing traffic does not.
Verification
Check the bytes yourself
Every release ships a manifest of SHA-256 hashes, and the application can re-check itself against it.
- The download page lists the SHA-256 of the package you are about to install.
- Inside the package, integrity.txt lists the SHA-256 of CommMonitor.exe and of the bundled driver nt6/ComDrv12Ex64.sys.
- Run the application with --integrity to re-check those files on disk; the exit code is the number of mismatches.
- The licence file is signed with RSA-2048 (PSS / SHA-256). The application only carries the public key, so a modified licence is rejected instead of accepted.
Honest limits
What we do not claim
Security pages usually list certifications. We would rather state exactly what is and is not verified today.
- We hold no certification from a driver-signing programme or a quality standard, and this site does not imply one.
- Code signing and antivirus reputation change with each build, so we make no claim about them here. Verify the SHA-256 of what you download, and tell us if a security product objects to the driver.
- Local tamper checks are a speed bump, not a guarantee. Any client that runs on a machine someone controls can eventually be patched.
- The driver is a kernel component: it needs administrator rights to install, and it is not a sandbox. Test it on a machine you can reimage.

