How I Built a Windows Security Monitor That Records Intruders Automatically Which You Can Review Using PowerShell

PowerShellカテゴリを表すパンダのイラスト PowerShell

This article is a technical explanation and implementation example created using AI. The code and procedures presented are based on primary sources, but have not been verified on actual hardware by the author. Behavior may vary depending on the environment and version. Based on primary sources, this article outlines how to safely and practically build and manage a mechanism in a Windows environment ranging from the detection of unauthorized access and login failures to automatic webcam recording and email notifications. We will examine manual execution, folder structures, and limitations in order.

Objective and Overview of this Mechanism

According to primary sources, this tool (SecurityMonitor-PowerShell) is a system that monitors Windows security event logs, automatically starts webcam recording via FFmpeg when a login failure (Event ID 4625) is detected, and sends email alerts to multiple destinations.

The diagram below illustrates the processing flow from monitoring to recording as described in the primary sources.

flowchart TD
    A[Windows Security Event Log] -->|Event ID 4625 detected| B(Threshold reached: 2 failed attempts in 30s)
    B -->|Email alert sent| C[Gmail SMTP to multiple addresses]
    B -->|Webcam recording starts| D[FFmpeg DirectShow]
    D -->|Footage saved| E[C:\SecurityCam\footage\]
    E --> F[Stop via Ctrl+Alt+S or stop.ps1]

Prerequisites, Warnings, and Requirements

When using and configuring this system, official information lists the following environment and preparatory steps.

  • OS: Windows 10 or Windows 11

  • Privileges: PowerShell must be run as an administrator

  • Tools: FFmpeg (obtained from the official website)

  • Notification Settings: Gmail account with two-factor authentication enabled and an app password

  • Devices: Built-in or external webcam

Additionally, the following limitations are noted in the primary sources.

  • It operates only while a user is logged in (PowerShell must be running).

  • Webcam cannot be accessed from the Windows login screen (OS-level restriction).

  • Webcam access via DirectShow requires a user session context.

  • Care must be taken when handling Gmail app passwords as they are stored within the script.

Folder Structure and File Layout

Official documentation requires files to be arranged in the following structure.

  • C:\SecurityCam\

    • monitor.ps1: Main monitoring script

    • hotkey.ps1: Hotkey listener (for Ctrl+Alt+S)

    • stop.ps1: Manual stop script

    • footage\: Destination directory for recorded video files

    • logs\

      • monitor.log: All event logs

      • ffmpeg_error.log: FFmpeg error output

Setup Procedure

The primary setup workflow based on official information is as follows.

  1. Installing FFmpegDownload from the official build site and extract to the specified path. Consider the following command to verify the installation.

    ffmpeg -version
    
  2. Verifying Webcam NameRun the following command to check the video devices section in order to identify the exact device name to use.

    ffmpeg -list_devices true -f dshow -i dummy 2>&1
    
  3. monitor.ps1Configuring SettingsUpdate the following variables at the top of the script to match your environment.

    • $gmailFrom: Sender email address

    • $gmailPass: Gmail app password

    • $alertTo1, $alertTo2: Alert destination address

    • $webcam: Detected webcam name

    • $ffmpegPath: FFmpeg executable path

  4. Creating folders and deploying scriptsUse PowerShell to create the required directories.

    New-Item -ItemType Directory -Force -Path C:\SecurityCam\footage
    New-Item -ItemType Directory -Force -Path C:\SecurityCam\logs
    

Operation and Usage

Since this is planned for verification in a Windows environment, the following procedures and output results are explanations based on primary source documentation.

To start monitoring, open PowerShell as an administrator, navigate to the working directory, temporarily change the execution policy, and launch the script.

cd C:\SecurityCam
Set-ExecutionPolicy Bypass -Scope Process -Force
.\monitor.ps1

If necessary, launch the hotkey listener in a separate window.

.\hotkey.ps1

To manually stop recording,stop.ps1execute the command, orhotkey.ps1press Ctrl+Alt+S while executing.

Example of Expected Console Output

The primary documentation provides the following example of console output upon successful operation.

  • Log at the start of monitoring (displaying threshold, lookback time, and polling interval)

  • Polling for failed login attempts within a specific period

  • Detection of "THRESHOLD HIT" when the threshold is reached (2 failures in 30 seconds), followed by email transmission and initiation of the recording process (displaying PID)

Email Alert Format

Emails sent when the threshold is exceeded include the detection time, computer name, account name, date, and storage path of the recording file to notify of potential unauthorized access.

Limitations and Future Improvements

The primary source also discusses the current system limitations and potential future improvements.

  • LimitationsRequires the user to be logged in and PowerShell to be running, and webcam access at the login screen is restricted due to OS-level limitations.

  • Planned Improvements:

    • Converting to a Windows service for pre-login monitoring

    • SMS alerts using Twilio

    • Email notification with attached video upon recording completion

    • Automatic startup via Task Scheduler upon login

    • Telegram bot notifications

Conclusion

This article outlines the components, setup, and operational procedures for a security monitoring system combining PowerShell, Windows Event Logs, and FFmpeg, based on the primary source.

The key prerequisites and constraints to check before execution are as follows:

  • PowerShell must be run with administrator privileges.

  • Gmail app passwords and webcam names must be verified in advance.

  • Due to Windows specifications, webcam recording at the login screen is not supported.

  • Operation has not been verified on physical hardware, so testing in each specific environment is required.

Reference Information

Document information

Article title
How I Built a Windows Security Monitor That Records Intruders Automatically Which You Can Review Using PowerShell
Published
Updated
Source
https://papanda925.com/?p=17954&lang=en

License: Text and original figures for which this site holds the relevant rights are available under CC BY 4.0 , unless otherwise noted. This article may include content created or edited with generative AI. If code has a separate license notice or a linked GitHub repository license, that license takes precedence for the code. Quotations, third-party materials, images, and trademarks are excluded from this license. Usage policy

Copied title and URL