
What it actually does
AFKSecurity is not an antivirus. It never opens your files, never scans them and never moves them. It watches what the system does, with particular attention to what happens while nobody is at the keyboard.
Behaviour, not signatures
There is no rule database to keep up to date and nothing to download every morning. Detection reads the context of use: the legitimate user, the usual program, the unusual one. A signed, perfectly legitimate tool can be turned against you. What gives it away is the use, not the binary.
Two witnesses before an accusation
Nothing concludes on its own. A suspicion only becomes an accusation when two independent sensors report it in the same instant. The difference was measured on our own bench: a factor of 250 between one source and two. That single rule is what separates a product that warns you from one that cries wolf.
Firewall rules that change behind your back
Firewall changes are read from the Windows log, which records the program that made them. An inbound rule created while nobody is at the keyboard, by a program unknown to the machine, is flagged.
Persistence, in all four of its usual forms
Services, scheduled tasks, registry run keys and permanent WMI subscriptions. WMI subscriptions leave no file on disk. None of these is suspicious on its own, since installers create services routinely: an alert requires several of them within the same minute, while nobody is at the keyboard.
Where the machine talks to
Outbound connections and DNS are watched, along with the hosts file and
the resolvers configured on each interface. Destinations are never kept in clear: a
salted fingerprint is stored instead, which is enough to see a pattern and not enough to
reconstruct where you went.
Interpreters with no window
On a normal machine most processes have no window, so an alert on that alone would flag the whole system. An interpreter running without a window is treated as a clue, not a verdict: it only counts when other sensors agree.
A keyboard that appears while you are away
A device that announces itself as a keyboard in the middle of the night, then an interpreter running with no window, is the exact shape of hardware whose only trick is to type. Two sensors speak, and it is the mesh that turns them into a verdict.
What happens when it decides something is wrong
It freezes, it does not kill
A suspected process is suspended, not terminated. Suspension is reversible and loses nothing: if the judgement was wrong, the program picks up where it left off. Killing a process that was halfway through writing your work is a second incident on top of the first.
It restores beside, never over
Recovered files are written next to the originals, under a new name. Nothing you have is overwritten by a decision the software made on its own.
A sealed local journal
Every finding is written to a local log where each line seals the one before it with a SHA-256 chain. A line cannot be altered or removed without breaking the chain, and the break is visible. Nothing leaves the machine.
A reading order, read from the mesh
Three levels: read this first, worth a look, for the record. The level depends on which hypotheses are active and which sensors support them, not on the wording of the line.
Exceptions that name an identity
An exception is granted to a publisher's signature, so it survives an update of that publisher, or to a path plus the binary's fingerprint, so that if the file changes the question is asked again. Never to a bare name. Every exception granted is recorded in the journal as a notable event.
A panic button, and a real stop
One shortcut, configurable, does everything it can to hand control back to you. And the protection can be stopped properly from the window, from the tray icon or from the command line.
In your language
The window and the installer are available in seven languages: English, Français, Deutsch, Español, Português, 中文 and 日本語. The language follows Windows on first start and can be changed at any time from the window.
What it does not do
Known limits of AFKSecurity.
- It is not an antivirus. No signatures, no on-demand scan, no file analysis, no quarantine. Keep the antivirus you have; this runs beside it.
- No email protection and no web browsing protection.
- It is not registered with the Windows Security Centre and does not appear there. Doing so requires a kernel driver that this product does not ship.
- An administrator can stop it. Stopping it is recorded and visible.
- It does not replace your backups, nor your Windows updates, nor your own judgement.
- No guarantee of result. No security software detects every attack.
Memory instead of processor
The trade
The substrate keeps a live state in memory instead of recomputing it. That state is what it costs you in memory, and it is what buys you the near absence of processor use. Software that holds nothing has to work everything out again on every event, and you pay for that in CPU, on the machine you are trying to use.
It settles where it needs to
There is no fixed amount to print here. The balance follows the machine, its hardware and what there is to watch. A quiet workstation and one running twenty programs do not call for the same state, and the substrate sizes itself accordingly.
The cost to everything else
System tracing adds a small cost to the programs being traced, which does not appear in AFKSecurity's own figures. That cost is measured on the traced programs during testing.
Nothing is kept between two runs
The state lives in memory and is rebuilt from nothing at every start. There is no internal database to grow, to corrupt, or to leak, and closing the product leaves nothing behind.
All of this is visible while it runs, on the Substrate tab. Every indicator on that tab is explained here.
What is never collected
These are not intentions. Each one is held by an automated test that fails if it stops being true.
- No keystrokes.
- No window titles.
- No program command lines.
- No full file path leaving a sensor.
- No network destination in clear text.
Nothing is uploaded. The software talks to us to activate a licence and then once a day to check the subscription is still valid; the body of each of those requests holds two fields: a fingerprint of the machine, and sometimes the licence key. What travels is described in the privacy policy.
MITRE ATT&CK coverage, with its gaps
25 mappings for 23 distinct techniques, each one declared with its reach: observed, by consequence, or partial. Seven sensors are listed with no technique where no exact match exists. The program can print the table itself.
The bench folder ships with the product
Most vendors publish a score from a laboratory. This one ships the exam. The test protocol, the dated measurements and the ledger of known limits are installed with the software, and you can replay them on your own machine, today. The failures are in there too: a file with no failures in it looks arranged.
Requirements
- Windows 10 or 11, 64-bit.
- Administrator rights to install the service. The window itself asks for none.
- An internet connection to activate a licence or start the trial, then once a day to check the subscription. It keeps working offline for weeks at a time.
- The Microsoft Edge WebView2 runtime, present on most systems. If it is missing, the installer reports it.