01
Watch the host
Build a live view of processes, TCP connections, and Windows startup Run keys.
On-device Windows breach signals
PrivacyGuard Breach watches the host signals that matter, alerts you when something changes, and helps you gather context without waiting for a cloud dashboard.
Processes
148
Connections
23
Alerts
1
New suspicious outbound connection
powershell.exe opened a new public remote not present in the baseline.
Collecting process, connection, and persistence context locally.
One response loop
01
Build a live view of processes, TCP connections, and Windows startup Run keys.
02
Rules assign a severity and reason when activity departs from the baseline or matches a suspicious pattern.
03
Get an immediate alert and run a local workflow that gathers the context you need to investigate.
Host visibility
See running processes and flag suspicious names, paths, and newly appearing activity.
Map public TCP connections back to the process that opened them and spot new destinations or unusual fan-out.
Optionally enrich remote addresses with a local GeoLite2 database and highlight contact with a new country.
Use editable YAML workflows to collect process, network, persistence, and Windows Security log context.
Teach an on-device model with Noise and Suspicious feedback. After a conservative warm-up, it can quiet recurring warning-level noise; critical alerts always remain active.
Network alerts resolve reverse DNS and perform RDAP/WHOIS automatically, then show the owner, network range, infrastructure class, evidence-risk score, and contributing reasons.
Immediate notification
New alerts appear in the app and can trigger a Windows toast and sound. Active and Quieted tabs keep learned warning noise reviewable. If you choose to configure one, critical alerts can also be sent to your own Discord webhook.
Critical alerts can start a local YAML workflow that snapshots high-CPU and living-off-the-land processes, established connections, Run keys, and recent Windows Security events.
Workflows execute commands on your machine. Automatic execution on critical alerts stays off until you complete the first-run checklist and opt in.
PrivacyGuard Breach identifies suspicious signals and changes. An alert is a reason to investigate—not proof that a breach occurred.
Early-access rules can produce false positives. This tool does not replace antivirus, endpoint protection, patching, backups, or professional incident response.
Core monitoring, workflows, and adaptive noise filtering run on your Windows PC. Model feedback and its bounded history remain local. Optional integrations send data only when you configure and use them.
Use Windows 10 or 11 on x64 hardware. Running elevated provides fuller network and Windows Security log visibility.
Country enrichment uses a local MaxMind GeoLite2 Country database. Optional packet snapshots require Npcap and Wireshark's tshark; capture files are written locally.
Discord notifications are off until you supply your own webhook. Alert title, detail, source, severity, and time are then sent to Discord under its terms and privacy policy.
Extract the ZIP and run breachguard.exe. Keep its configuration and workflow files with the application.