On-device Windows breach signals

See suspicious activity. Start triage fast.

PrivacyGuard Breach watches the host signals that matter, alerts you when something changes, and helps you gather context without waiting for a cloud dashboard.

Don't have a license yet? Get Screen Shield — $3.69
Windows x64Early accessExisting license required
PrivacyGuard Breach dashboard showing a critical outbound-connection alert and an active triage workflow.
PrivacyGuard BreachWatching

Processes

148

Connections

23

Alerts

1

Critical signaljust now

New suspicious outbound connection

powershell.exe opened a new public remote not present in the baseline.

Triage workflow running

Collecting process, connection, and persistence context locally.

One response loop

Watch. Alert. Triage.

01

Watch the host

Build a live view of processes, TCP connections, and Windows startup Run keys.

02

Surface the signal

Rules assign a severity and reason when activity departs from the baseline or matches a suspicious pattern.

03

Start triage

Get an immediate alert and run a local workflow that gathers the context you need to investigate.

Host visibility

The signal, its source, and what changed.

Process awareness

See running processes and flag suspicious names, paths, and newly appearing activity.

Connection ownership

Map public TCP connections back to the process that opened them and spot new destinations or unusual fan-out.

Geo-aware baselines

Optionally enrich remote addresses with a local GeoLite2 database and highlight contact with a new country.

Response workflows

Use editable YAML workflows to collect process, network, persistence, and Windows Security log context.

Local noise filtering

Teach an on-device model with Noise and Suspicious feedback. After a conservative warm-up, it can quiet recurring warning-level noise; critical alerts always remain active.

Automatic IP evidence

Network alerts resolve reverse DNS and perform RDAP/WHOIS automatically, then show the owner, network range, infrastructure class, evidence-risk score, and contributing reasons.

Immediate notification

An alert should find you.

New alerts appear in the app and can trigger a Windows toast and sound. Active and Quieted tabs keep learned warning noise reviewable. If you choose to configure one, critical alerts can also be sent to your own Discord webhook.

Windows toast and system sound
In-app severity-ranked alert feed
Quiet hours and per-rule mute controls
Optional Discord webhook for remote notification

Triage while the context is fresh

Critical alerts can start a local YAML workflow that snapshots high-CPU and living-off-the-land processes, established connections, Run keys, and recent Windows Security events.

Workflows execute commands on your machine. Automatic execution on critical alerts stays off until you complete the first-run checklist and opt in.

Know what the signal means

PrivacyGuard Breach identifies suspicious signals and changes. An alert is a reason to investigate—not proof that a breach occurred.

Early-access rules can produce false positives. This tool does not replace antivirus, endpoint protection, patching, backups, or professional incident response.

Core monitoring, workflows, and adaptive noise filtering run on your Windows PC. Model feedback and its bounded history remain local. Optional integrations send data only when you configure and use them.

Requirements and optional integrations

Use Windows 10 or 11 on x64 hardware. Running elevated provides fuller network and Windows Security log visibility.

Country enrichment uses a local MaxMind GeoLite2 Country database. Optional packet snapshots require Npcap and Wireshark's tshark; capture files are written locally.

Discord notifications are off until you supply your own webhook. Alert title, detail, source, severity, and time are then sent to Discord under its terms and privacy policy.

Download details
Version
v0.7.1
Download
8.2 MB
Platform
Windows 10/11 · x64
SHA-256
f9772d379eaab1824040e08a8aff9384e260b0a5f3c4d80928ea01b675850aa6

Extract the ZIP and run breachguard.exe. Keep its configuration and workflow files with the application.