Real scenarios built around what Nocturn actually does — not hypotheticals. Every feature mentioned here ships in V1 today.
If you run Ollama, Claude Code, MCP servers, browser-automation agents, or IDE assistants, you've got AI tools talking to the network constantly — most of it legitimate, some of it you may not even remember installing. AI Watch gives you one live table of every AI process on the machine and every outbound connection to a known LLM endpoint, so "what's phoning home right now?" has an actual answer instead of a guess.
Trust the tools you use daily by allowlisting them — or better, trust the whole publisher once (e.g. everything validly signed by Anthropic), so future updates don't re-trigger a flag. Anything genuinely new stands out immediately, in amber or red, the moment it appears.
Clipboard hijacking is a quiet, common attack: malware sits in the background, watches your clipboard, and the instant you copy something valuable, swaps it for something the attacker controls. You paste, you act on it, and by the time you notice, the damage is done. The most common real-world target is a cryptocurrency wallet address — but the underlying attack applies to any sensitive data you copy and paste.
Clipboard Guard watches for exactly that swap and warns you the moment it happens, offering to restore what you actually copied — before anything is sent. It covers wallet-address formats for BTC, ETH/EVM, XRP, LTC, TRX, and DOGE, and runs on by default with nothing to configure. Sophisticated kernel-level malware could still bypass a user-mode guard, so it's not a substitute for double-checking what you paste — but it stops the vast majority of real-world clipboard hijackers.
A new AI agent, an untrusted script, a model you just downloaded — before running any of it, a lot of Nocturn users combine two features that weren't designed to work together but do it very well:
Open the Drives tab and take your backup or personal-data drive offline — one click, enforced by Windows itself. Nothing running on the machine can read, write, or even see that drive until you bring it back online. No exceptions, no bypass.
AI Watch flags any unrecognised AI process or LLM connection the moment it appears. Kill it on the spot — and even if it had slipped past for a few seconds, the drive holding your real files was never reachable in the first place.
AI Watch is the early warning. Drive Control is the wall behind it — belt and braces, not blind trust in either one alone.
Unsanctioned AI tools showing up on work machines — an assistant nobody approved, an agent someone installed to "just try it," a script quietly relaying data to an LLM endpoint — is a real and growing risk for small teams without a dedicated security function. Nocturn's Script Provenance flags automation started by something other than you or a trusted AI (a service, a scheduled task, an unexplained origin), and AI Watch surfaces every LLM connection regardless of which app made it.
It's not an enterprise device-management platform — Nocturn is one machine, one licence, genuinely local-first with no central dashboard. For a solo operator or a very small team checking their own machines one at a time, that's often exactly the right amount of tool.
Nocturn's file scanner only auto-quarantines when two independent detectors agree — a single suspicious signal becomes a reviewable alert, not an automatic deletion. Combined with running in user mode, no kernel driver, and never phoning home, it's built to sit quietly at ~40 MB RAM and under 0.1% CPU, and only interrupt you for something that actually matters.