SYSTECH BOOSTER 1.0.0-preview.1 — ARCHITECTURE AND SAFETY This is a newly implemented Windows utility, not the earlier iMON/SysTech monitoring agent repackaged, and not a pixel-perfect image used as a UI. Every UI control is HTML/CSS/JavaScript connected to a Go loopback engine. The interface uses the requested dark navy / cyan / magenta HUD direction. Architecture - Windows executable compiled for GOARCH=amd64 and GOARCH=386, CGO_ENABLED=0. - Win32 calls through the Go standard library; no third-party Go modules. - Embedded UI served on a randomly allocated 127.0.0.1 TCP port. - Edge app-window launch when found; default-browser fallback. - Launch capability is generated from 32 cryptographically random bytes. - One-time presentation through URL fragment; JS removes it from browser history. - HttpOnly + SameSite=Strict host-only session cookie; random CSRF header. - Exact Host and Origin validation; no permissive CORS; no remote listening. - JSON size limit, known-field validation, explicit action allow-list. - No shell command endpoint, no script execution from client input, no telemetry. - Only a fixed, non-interpolated PowerShell/CIM hardware script runs once. - Optional TCP diagnostic sends network requests to the user-entered hostname. - No OS service, scheduled task, auto-update agent, or persistence is installed. Native APIs CPU: GetSystemTimes (sample deltas). RAM: GlobalMemoryStatusEx; processes via EnumProcesses/GetProcessTimes/ QueryFullProcessImageNameW/GetProcessMemoryInfo. Process safety: token SID, ProcessIdToSessionId, IsProcessCritical, visible window enumeration, system/known-protected app exclusions and process creation-time identity revalidation before an action. CPU control: SetPriorityClass(BELOW_NORMAL_PRIORITY_CLASS), with original priority saved for restoration in the current engine session. Graceful close: WM_CLOSE to the chosen app's visible windows; no force-kill. Memory: EmptyWorkingSet only for the explicitly chosen eligible process. Storage: GetDiskFreeSpaceExW on local fixed drives; scan previews enumerate only supported current-user folders. No junction traversal or hard links. Recycle: SHFileOperationW with fully qualified double-NUL terminated paths, FOF_ALLOWUNDO + FOF_WANTNUKEWARNING + FOF_NO_CONNECTED_ELEMENTS. Native confirmation is preserved and can occur separately for each file. Empty bin: SHEmptyRecycleBinW with native confirmation retained. Network: GetIfTable native counters; DNS resolver flush; TCP connect latency. Important behavior - Lower priority does not itself guarantee lower CPU percentage. - Working-set trim does not deallocate application memory or fix leaks. - Recycle Bin transfers do not necessarily free physical disk space. - Windows can offer permanent deletion for an unrecyclable file; cancel that native prompt to preserve recovery. SysTech does not suppress this warning. - Emptying Recycle Bin affects ALL of that user's bin contents. - Every file identity/size/mtime/path is checked again after a scan. This is defense in depth, not a claim of an independently audited race-free cleaner. Do not concurrently modify scanned folders during deletion. - A scan is bounded (40 seconds, 100,000 entries, 3,000 matches), expires after 15 minutes, and is invalidated after a deletion attempt. Max 300 selections. - No automatic clearing of browser profiles, login cookies, system updates, registries, page files, standby lists, AV, services, TCP tuning or adapters. - Network settings and startup changes use Windows settings UI explicitly. - Before/after values are observations, not causal performance guarantees. Known limitations / intended targets - Windows 10/11, Windows Server 2016+ with desktop/browser: intended, not runtime-certified here. Server Core and pre-Windows-10 systems not targeted. - Use x64 on x64 Windows. 32-bit counters/process views are not a substitute for the native 64-bit build on large-memory x64 systems. - GPU name only: no GPU load/VRAM, temperatures, fan sensors, RAM clock or disk I/O throughput in this release. No fake sensor values are displayed. - GetSystemTimes has processor-group caveats on >64 logical CPU systems; multi-group server accuracy is not certified. - GetIfTable uses 32-bit traffic counters; very high-throughput links can wrap between samples. Link speed is driver-reported and may be limited. VPN/virtual interfaces and physical interfaces can count the same traffic; dashboard totals sum active interfaces, not Internet-only traffic. - Desktop/Documents redirection, OneDrive reparse folders and network paths are intentionally excluded instead of followed. Custom scan roots are not exposed by the API. Real browser cache clearing is not implemented. - GUI owner process list excludes inaccessible processes; it is not a complete administrative service inventory. - Closing the UI leaves engine active until 10 minutes without API requests. Settings → Stop & Exit terminates it immediately. - Each engine uses a unique session-cookie name to avoid instance collisions. - Local activity log is append-only, not tamper-proof; cap/rotation is not implemented. Review %APPDATA%\SysTechBooster\activity.jsonl periodically. - Unsigned preview executable; not a Windows certification or malware scan. Build environment actually used for supplied binaries Linux host, Go 1.23.2, cross-compiled Windows PE32 and PE32+ binaries. Go 1.23.2 is the installed build tool, not a claim that it is the current supported Go security release. Before distribution rebuild with a currently maintained Go version and run the Windows acceptance checklist. The local API tests, fixture UI interactions, ZIP integrity checks and PE architecture checks are described in TESTING.txt. No native Windows run was performed in this Linux environment. Primary technical references https://learn.microsoft.com/en-us/windows/win32/api/psapi/nf-psapi-emptyworkingset https://learn.microsoft.com/en-us/windows/win32/api/processthreadsapi/nf-processthreadsapi-setpriorityclass https://learn.microsoft.com/en-us/windows/win32/api/shellapi/ns-shellapi-shfileopstructw https://learn.microsoft.com/en-us/windows/win32/api/shellapi/nf-shellapi-shemptyrecyclebinw https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/ipconfig https://go.dev/wiki/Windows