1 · Download & run the installer
After purchase you'll get an email with your download link and licence key. Download NocturnSetup.exe.
Double-click NocturnSetup.exe and follow the prompts. It installs to your user profile — no admin rights needed for everyday use.
When it finishes, Nocturn opens automatically and a shield icon appears in your system tray (bottom-right, near the clock).
2 · First launch — what you'll see
Nocturn opens its main window and adds a shield icon to your system tray. From that tray icon you can open the window, pause monitoring, or quit. Closing the window doesn't quit Nocturn — it keeps watching quietly in the background.
Tip: drag the Nocturn tray icon onto the always-visible part of your taskbar so it's one click away. Nocturn only speaks up when something needs your attention.
3 · Enter your licence key
On first run, Nocturn asks for your licence key. Copy it from your purchase email — it looks like NOCTURN1.xxxx.xxxx.
Paste it in and click Activate. Your licence binds to this machine and is stored securely by Windows — not in the app folder.
New PC later? Deactivate on the old machine (Settings → Licence), then activate on the new one with the same key. One seat per licence. Lost access to the old machine? Email
[email protected].
4 · AI Watch — how to read it
AI Watch is the heart of Nocturn: a live table of every AI tool, agent, and script running on your machine, and every outbound connection it makes to a large-language-model service. See what AI is doing on your machine — and decide what's allowed.
- Trusted (green) — a process you've allowlisted, or one signed by a publisher you trust. It stays quiet.
- Flagged (amber / red) — something new or unrecognised: an AI process, LLM connection, or script Nocturn can't attribute to you or a trusted tool.
What to do: for anything you recognise, click Allowlist — or trust the whole publisher (e.g. every binary validly signed by "Anthropic, PBC"). Trusting a publisher is safer than trusting a filename. Once your known tools are trusted, anything genuinely new stands out immediately.
Block or kill any process with one click. Cut a process's network access, or terminate it entirely. Optional auto-kill mode handles unauthorised processes for you, with a safety guard that stops it fighting a respawn loop.
Privacy: detection is passive — Nocturn reads the process and connection lists Windows already keeps. It does not read the contents of your AI conversations or decrypt any traffic.
5 · Clipboard Guard — nothing to configure
Real-time protection against clipboard-hijacking malware. It's on by default and needs no setup. Clipboard-hijacking malware watches your clipboard and silently swaps sensitive copied data for something the attacker controls — the most common case is a copied crypto wallet address being swapped for the attacker's, so you paste the wrong address and funds go to them.
Nocturn watches for that swap and, the instant it happens, warns you and offers to restore the address you actually copied — before you send anything. It covers the major wallet formats: BTC, ETH/EVM, XRP, LTC, TRX, DOGE and more, and defeats 99%+ of commodity clipboard-hijacking attacks seen in the wild.
Honest limit: sophisticated kernel-level malware could bypass any user-mode guard. Clipboard Guard stops the vast majority of real-world clipboard hijackers — it is not a guarantee against every possible attack. Always eyeball the first and last few characters of an address before you send.
6 · File Scanner & quarantine
Open the Scan tab to check files with multi-layer detection:
- Quick scan — the places malware actually lands (Downloads, Desktop, Temp, startup folders, running programs). Fast — start here.
- Full scan — every fixed drive. Thorough but slow; run it occasionally.
- Targeted — point it at a single folder or file.
Anything suspicious goes into an encrypted quarantine vault — locked away so it can't run, but recoverable if it turns out to be a false positive. Nocturn is deliberately quiet: it only auto-quarantines when two independent checks agree, so it rarely cries wolf.
Worked example — you get a quarantine alert. Say a scan flags
svhost32_update.exe sitting in your Downloads folder. Here's a sane way to work through it:
- It's already quarantined — the file can't run while it's in the vault, so there's no rush. Take your time.
- Check the name and the location. A real Windows process is
svchost.exe, and it lives in System32 — not a misspelled name sitting in Downloads. That mismatch alone is a strong tell.
- Search the exact filename and the hash shown in the alert. A well-known threat usually turns up results immediately; something genuinely new might not, which is itself useful information.
- Still not sure? Leave it quarantined. It costs you nothing to wait — you can restore it later in a click if it turns out to be nothing. Deleting something you actually needed is the one mistake that's hard to undo, so let "unsure" default to "leave it locked away," not "delete it."
7 · Autostart
By default Nocturn starts with Windows so you're protected from boot. To change it, go to Settings → Start with Windows and toggle it on or off. That's it — the setting takes effect on your next sign-in.
You're set. Nocturn now runs quietly in your tray and only speaks up when something needs your attention. Remember: Nocturn is a complement to Windows Defender — not a replacement. Keep Defender on; Nocturn adds the AI-awareness and clipboard protection Defender doesn't have.