NiteWatch
Somebody's knocking on your door at 3 a.m. Here's who.
Consumer antivirus tells you it "quarantined a threat" and leaves you exactly as informed as you were before. That's not an answer, it's a receipt. NiteWatch is the version that tells you the story: this PDF spawned a script, that script is phoning home to a server flagged for malware control, and it's been rewriting your Documents folder for the last nine minutes. Everything the enterprise world calls EDR, minus the SOC analyst you don't have and the jargon you shouldn't need.
Who's talking, and to whom. A permanent, process-attributed log of every outbound connection your machine makes — which program, which server, which domain, when. Not a firewall popup you click through at 2 a.m., a ledger you can go read later.
The whole causal chain, in plain English. Alerts show how it happened, start to finish, instead of a jargon blob with a severity color on it. If you can read a sentence, you can read the alert.
Private by design. Everything is analyzed on your own machine. Threat intelligence gets pulled down; your data never goes up. No kernel driver, ever, in this product line.
Status: in development. The flight recorder — the causal event graph and the "who's talking?" connection ledger with its local dashboard — is built and running on Windows. Detections and alerts come next, then one-click response with an undo path. There's no public build to download yet; if you want to be on the list when there is, say so.