← Back to Work

NiteWatch

Somebody's knocking on your door at 3 a.m. Here's who.

Consumer antivirus tells you it "quarantined a threat" and leaves you exactly as informed as you were before. That's not an answer, it's a receipt. NiteWatch is the version that tells you the story: this PDF spawned a script, that script is phoning home to a server flagged for malware control, and it's been rewriting your Documents folder for the last nine minutes. Everything the enterprise world calls EDR, minus the SOC analyst you don't have and the jargon you shouldn't need.

Who's talking, and to whom. A permanent, process-attributed log of every outbound connection your machine makes — which program, which server, which domain, when. Not a firewall popup you click through at 2 a.m., a ledger you can go read later.

The whole causal chain, in plain English. Alerts show how it happened, start to finish, instead of a jargon blob with a severity color on it. If you can read a sentence, you can read the alert.

Private by design. Everything is analyzed on your own machine. Threat intelligence gets pulled down; nothing about your machine goes up on its own. Two features can ask a third party — a registration lookup for one address, and an optional reputation check on one file fingerprint that needs your own API key — and neither does anything until you press it. No kernel driver, ever, in this product line.

Built since: an Explain everything toggle describing 52 common programs in plain English for people who don't work in this field, a Test me drill that fires all fourteen warnings so you can read what each means before meeting one for real, an Ask about this button that turns any alert into a question for the assistant of your choice (copied to your clipboard, never sent), and the known limitations and roadmap compiled into the binary so they describe the build you're running rather than whatever a web page last claimed.

Status: in development. The flight recorder, the causal event graph, the rule engine with its fourteen detection rules, the plain-English alert UX and one-click response are all built and running on Windows. What's missing is everything around it: the binary is unsigned, there's no installer and no service, it's Windows-only, and the false-positive rate over a long real session is still unmeasured — that soak is running now. A pre-release build is now downloadable — unsigned, warned about by Windows, and honest on the page about everything it hasn't earned yet.