Offline
You can try to google IDS for Windows possibly. This one is Linux based and claims to be easy to use. I like the name of the company. Skynet....
Offline
This one is called Suricata. Also open source and includes a Windows .msi installer which means it could be deployed using policy.