How I Built a Windows Security Monitor That Records Intruders Automatically Using PowerShell
The Story That Started It All Years ago, I watched a video that stuck with me. An engineer had spent hours building an entire software from scratch. The moment he stepped away from his PC, someone who had been observing his pattern walked over, plugged in a flash drive, and copied the entire work. The painful part was not just the theft. It was how it happened. The spy had been watching. He knew…
This story recounts the process of creating a security monitoring system for Windows computers using PowerShell. The author was inspired by a video of an engineer whose work was stolen when someone observed his patterns. This led the author to research ways to enhance PC security without relying on external software.
The resulting tool, built solely in PowerShell, automatically notifies the user of three failed login attempts and begins recording the webcam silently. The unauthorized user cannot stop the recording without access to the specific code or a built-in keyboard shortcut. The system utilizes Windows Security Event Log to monitor failed logins and sends email alerts using Gmail SMTP. Webcam recording is achieved through FFmpeg, a powerful multimedia framework.
The author encountered several challenges during the development process. Initially, the event count kept growing due to a misconfigured time window. This was resolved by using a sliding 30-second window instead. Another issue arose when FFmpeg crashed silently, which was solved by switching the FFmpeg process to a minimized window rather than hidden.
Additionally, the author discovered that running two scripts simultaneously could cause conflicts, so it's important to ensure only one instance of the program runs at a time.
The author also notes a limitation of the Windows architecture, which only allows webcam recording to start after someone logs in. This means the tool cannot begin recording before the user authenticates. A potential future improvement could be a Linux port, as it would allow for more comprehensive security monitoring.
The full code for the security monitoring system is available on GitHub, and the author provides detailed instructions for setting up the tool. Despite encountering bugs and limitations, the author emphasizes the value of curiosity and problem-solving in the development process.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.