AFKSecurity

Local substrate cybersecurity agent · Available
1.0.5 Current version · 4 October 2026

The installed version is shown under About in the software, and these notes appear in its Updates tab.

Releases

1.0.5 4 October 2026 Recommended

An optional password for exceptions, a warning when the vault has been tampered with, no more slowdown when a program keeps reopening the microphone or the camera, and no more network connections from the protection service.

Added

  • An optional password for exceptions, in Settings. Once it is set, granting an exception needs it, and so does ticking Don't ask me again for this program. Someone sitting at your computer, or a program driving the window, can no longer tell AFKSecurity to leave a program alone. Removing an exception never needs it. The password itself is never stored: only a slow, salted fingerprint of it, kept in the vault. Each wrong attempt is written to the log, and after three in a row the wait between attempts grows.
  • If you forget the password, the licence key of that computer replaces it. Details: Why does the software ask me for a password?
  • If the vault where AFKSecurity keeps its settings is erased, modified, replaced, or put back from an older copy, AFKSecurity says so at the next start: a red banner in the window, a Windows notification and a line in the log.

Changed

  • The protection service no longer opens any network connection. To check who published a program, it used to let Windows fetch certificate revocation lists over port 80, which a firewall could show as many short connections in a row. It now reads only the answers Windows already keeps in its cache. Details: What AFKSecurity connects to and writes.
  • The report reads more calmly, in all seven languages. Hypotheses say what is possible instead of stating it as fact, words such as keylogger only appear when something of the kind was actually seen, and an internal check of the network cut rule stays in the log instead of the report.
  • During bursts of activity the log is written in one go, with the file kept open, instead of being opened and closed for every line. Nothing is held back in memory: a power cut still loses no line.
  • The installer now uses English when Windows is set to a language it does not offer. It used French.
  • After Release this machine's seat, the licence key is cleared from the screen.

Fixed

  • The protection service could slow down over a few hours when a program took the microphone, the webcam or the screen again every few seconds: each time added a new entry and a new line in the log. The same program on the same device now counts once, and the log mentions it once each time you leave or come back, with a reminder at most once an hour.
  • Components signed by Microsoft are no longer reported as suspicious: Microsoft Defender's own library and its definition updates, and the Edge updater opening a firewall port.
  • Three antivirus products (Huorong, Rising, then Microsoft Defender) flagged the 1.0.4 installer. The cause was on our side: the translation table, full of security terms, was stored as plain text inside the programs. It is now compressed, and 1.0.5 is not flagged.

1.0.4 2 October 2026

Decoy files explained and removable, a folder of your choice for exports, and the licence time remaining on the licence screen.

Changed

  • Decoy files are now placed only in your own folders: the root of Documents, the root of Pictures and the root of your user folder. Earlier versions could put some inside another application's folder, in Documents or in AppData. Those files are removed when 1.0.4 starts.
  • Settings has a new Decoy files section: what they are for, where each one is, and a button to remove them or put them back. Removing them is written to the log, so it cannot go unnoticed.
  • Saving the report, the log, the MITRE table or the incident file now asks you for a folder, instead of always using Documents.
  • The licence screen now has two lines: the days of use left without contacting the server (35 at most, the only number shown until now), and the licence time remaining, with its end or renewal date. The second line is filled in after the next daily licence check.
  • The window's display component (Microsoft WebView2) now starts with its background network services turned off: component updates, crash reports, translation and the other services a browser runs on its own. AFKSecurity's own connections are unchanged: the daily licence check, and the update check when you ask for it. Details: What AFKSecurity connects to and writes.
  • The report, the MITRE table and the incident file are now written in the language of the window. They were in French only.
  • Several messages in the window were reworded to be clearer. The Portuguese, Chinese and Japanese translations now use the same terms throughout.

Fixed

  • In Settings, the list of programs you can grant an exception to kept changing on its own and was hard to select from. It now lists every running program in alphabetical order, and only changes when you open the page or click Refresh the list. It is also shown in the window's colours instead of white.
  • Uninstalling now removes the decoy files too. Earlier versions left them behind.

1.0.3 24 September 2026

The whole interface now speaks your language, including the Proof tab, which still showed some text in French.

Fixed

  • The MITRE ATT&CK table in the Proof tab described what each sensor sees in French only. It is now translated into all seven languages.
  • Some journal lines and incident replays (new devices, files replaced in a protected folder, withdrawn permissions, trusted programs) showed a technical key instead of a sentence. They now read normally.
  • In German, Spanish, Portuguese, Chinese and Japanese, a few texts still used the old word for sensor. The wording is now the same everywhere.

1.0.2 23 September 2026

Stable memory over long uptimes, a simple status tab, and a Windows notification when AFKSecurity is waiting for your answer.

Fixed

  • The service's memory grew steadily for as long as the computer stayed on. Two sensors that read the Windows event log (firewall and startup entries) left part of each reading open, and Windows kept it in memory. Every reading is now closed, and memory stays flat. Detection is unchanged.
  • The sensors do less work on each cycle: several checks that ran many times per second no longer allocate memory to do it.

Added

  • A Status tab, now the first one: whether protection is active, and what, if anything, needs your attention. The detailed view is one click away.
  • When AFKSecurity asks whether an activity is yours, Windows shows a notification. Clicking it opens the window with the question.
  • Each section of the Report tab shows its first entries, with a Show more button for the rest.

Changed

  • “Don't ask me again for this program” is ticked by default when you answer “it's me”. The program is then remembered until you remove it in Settings, under Programs you allowed.
  • The interface says sensor where it used to say organ.

1.0.1 22 September 2026

Fewer false alarms and lower resource use on busy computers. AFKSecurity recognises trusted programs from the start and freezes a program only when files have actually been lost.

Changed

  • A program is frozen only when a real loss is detected: files renamed to an extension it never read, files overwritten in place, or one of your folders being emptied. A high rate of file writes is no longer enough on its own.
  • Web browsers, code editors, Windows and OneDrive are recognised as trusted programs from the first second. Recognition requires both the program name and a verified publisher signature. Their activity is still recorded in the journal, but they are not frozen. Windows tools commonly misused by attackers, such as PowerShell and the command prompt, are not included.
  • For the first three minutes after startup, AFKSecurity observes and records without freezing programs or cutting the network, unless files are actually being lost.

Fixed

  • Answering “it's me” now applies to the program for the whole session, including after it restarts.
  • On computers running several hundred programs, the substrate could run out of energy and remain in its critical state. Its energy budget now scales with the size of the machine.
  • The window refreshes fifteen times per second, and its drawing pauses while it is hidden.
  • The Host panel shows the processor and memory used by the AFKSecurity service.

1.0.0 18 September 2026 First release

First public release. A local security agent that watches how Windows behaves, freezes what has no business running, and writes a sealed journal you can read yourself.

What it does

  • Watches system behaviour with no signature database: files and decoys, persistence, devices, network, processes and windows, browser extensions.
  • Freezes a program and contains it through Windows firewall rules when two separate sensors agree that something is wrong, never on one alone.
  • Keeps a local journal sealed line by line with a SHA-256 chain, so that a missing line can be detected.
  • Writes a weekly AFK report: a summary of what it saw while you were away.
  • Publishes its MITRE ATT&CK mapping, including the techniques it does not cover.
  • Ships its bench folder: the test protocol, the dated measurements and the ledger of known limits, so you can replay them on your machine.
  • Speaks seven languages.

Licensing

  • 14-day trial, complete, no payment method and no account.
  • Online activation, then a daily check. The body of each request holds two fields: a fingerprint of the machine, and sometimes the licence key.
  • The licence is tied to the hardware, not to the installed system: reinstalling Windows finds it again on its own.
  • It keeps working offline for weeks at a time.
  • When a subscription or a trial ends, the software does not stop. It switches to witness mode: it keeps observing and reporting, and stops acting.

Updates

  • Nothing is downloaded or installed without you asking. What comes down is checked twice before it runs: its fingerprint against a manifest signed by the publisher, then its code signature against the copy already installed.
  • No version older than the one installed is ever accepted.

How to read this page

  • Added : something the software did not do before.
  • Changed : something it now does differently.
  • Fixed : something that was wrong.
  • Security : a fix that closes a hole. Install it the same day.

Versions are numbered major.minor.patch.

Share: Facebook · X · Reddit · LinkedIn