Use cases

Who Nocturn is for, and how they use it.

Real scenarios built around what Nocturn actually does — not hypotheticals. Every feature mentioned here ships in V1 today.

Developers & power users

Running local AI and agents, and wanting to know what they're actually doing

If you run Ollama, Claude Code, MCP servers, browser-automation agents, or IDE assistants, you've got AI tools talking to the network constantly — most of it legitimate, some of it you may not even remember installing. AI Watch gives you one live table of every AI process on the machine and every outbound connection to a known LLM endpoint, so "what's phoning home right now?" has an actual answer instead of a guess.

Trust the tools you use daily by allowlisting them — or better, trust the whole publisher once (e.g. everything validly signed by Anthropic), so future updates don't re-trigger a flag. Anything genuinely new stands out immediately, in amber or red, the moment it appears.

AI WatchPublisher trustBlock & Kill
Anyone copying sensitive data

Stopping clipboard data from being silently swapped

Clipboard hijacking is a quiet, common attack: malware sits in the background, watches your clipboard, and the instant you copy something valuable, swaps it for something the attacker controls. You paste, you act on it, and by the time you notice, the damage is done. The most common real-world target is a cryptocurrency wallet address — but the underlying attack applies to any sensitive data you copy and paste.

Clipboard Guard watches for exactly that swap and warns you the moment it happens, offering to restore what you actually copied — before anything is sent. It covers wallet-address formats for BTC, ETH/EVM, XRP, LTC, TRX, and DOGE, and runs on by default with nothing to configure. Sophisticated kernel-level malware could still bypass a user-mode guard, so it's not a substitute for double-checking what you paste — but it stops the vast majority of real-world clipboard hijackers.

Clipboard GuardOn by defaultNo setup required
Testing anything you don't fully trust yet

Two layers of protection when you're about to run something new

A new AI agent, an untrusted script, a model you just downloaded — before running any of it, a lot of Nocturn users combine two features that weren't designed to work together but do it very well:

1

Before you hit run

Open the Drives tab and take your backup or personal-data drive offline — one click, enforced by Windows itself. Nothing running on the machine can read, write, or even see that drive until you bring it back online. No exceptions, no bypass.

2

If something shows up

AI Watch flags any unrecognised AI process or LLM connection the moment it appears. Kill it on the spot — and even if it had slipped past for a few seconds, the drive holding your real files was never reachable in the first place.

AI Watch is the early warning. Drive Control is the wall behind it — belt and braces, not blind trust in either one alone.

AI WatchDrive ControlBlock & Kill
Small teams

Catching "shadow AI" before it becomes a data problem

Unsanctioned AI tools showing up on work machines — an assistant nobody approved, an agent someone installed to "just try it," a script quietly relaying data to an LLM endpoint — is a real and growing risk for small teams without a dedicated security function. Nocturn's Script Provenance flags automation started by something other than you or a trusted AI (a service, a scheduled task, an unexplained origin), and AI Watch surfaces every LLM connection regardless of which app made it.

It's not an enterprise device-management platform — Nocturn is one machine, one licence, genuinely local-first with no central dashboard. For a solo operator or a very small team checking their own machines one at a time, that's often exactly the right amount of tool.

AI WatchScript provenanceSystem Apps
Anyone who values a quiet machine

Not wanting a noisy antivirus that cries wolf

Nocturn's file scanner only auto-quarantines when two independent detectors agree — a single suspicious signal becomes a reviewable alert, not an automatic deletion. Combined with running in user mode, no kernel driver, and never phoning home, it's built to sit quietly at ~40 MB RAM and under 0.1% CPU, and only interrupt you for something that actually matters.

File Scanner + VaultTwo-detector rule~40 MB RAM
Recognise yourself in more than one of these? That's normal — most Nocturn users combine several of the above without thinking about it as "use cases," just as how they work. See the full feature list on the Nocturn page, or jump straight to the setup guide.