Local-first ransomware & bad-behavior guard for Windows.
Runs in your system tray, watches high-value folders, uses canary files for high-confidence alerts,
and generates clean HTML reports with Security Status + Incident Cards (last 24h).
SilentHelm is not a full antivirus replacement. It’s an explainable, local-first “second set of eyes” that helps you spot suspicious behavior early.
Always available, lightweight, and designed to be understandable.
Focuses on patterns (bursts, suspicious process launches, and canary touches)—not signature matching.
Logs, incidents, and reports are stored locally under your profile. No cloud by default.
A small, realistic security tool for Windows that aims to be useful for normal users and power users.
| Action | What it does |
|---|---|
| Status | Shows the current state (last 24h summary) in the tooltip. |
| Run report | Generates the HTML report and opens it in your default browser. |
| Reload | Reloads SilentHelm.config.json and applies changes. |
| Open log file | Opens SilentHelm.log.jsonl in your default editor. |
| Exit | Stops monitoring and exits cleanly. |
SilentHelm is designed to be practical: collect local signals, raise explainable alerts, and present them in a clean report.
Watches high-value folders and new process launches for behavior patterns commonly used in real attacks.
Detects file bursts and canary touches, then creates a local incident record (rate-limited).
Generates a clean HTML report with Security Status + Incident Cards, including “what to do now” guidance.
SilentHelm runs on Windows 10 / 11 (64-bit). Admin rights are recommended for deeper visibility, but it can still run without elevation.
Current release: Public v1
Release date: 2025-01-01
SilentHelm has been downloaded 91 times.
SilentHelmTray.exe — start tray monitoringSilentHelm.config.json (Reload applies changes)By default, SilentHelm writes everything under your local profile:
%LOCALAPPDATA%\SilentHelm\SilentHelm.log.jsonl — event log%LOCALAPPDATA%\SilentHelm\Incidents\* — incident bundles%LOCALAPPDATA%\SilentHelm\report.html — HTML report%LOCALAPPDATA%\SilentHelm\SilentHelm.config.json — configurationNo data is sent to any server unless you add an opt-in cloud feature in the future.
SilentHelm started as a practical “local-first” security companion: a tool focused on visibility and explainable alerts.
SilentHelm is a best-effort defensive tool. No software can guarantee detection or protection.
For feedback, bug reports, or feature suggestions:
SilentHelm.log.jsonl (redact sensitive info).