This article is a technical explanation and implementation example created using AI. The code and procedures presented are based on primary sources, but have not been verified on actual hardware by the author. Behavior may vary depending on the environment and version. Based on primary sources, this article outlines how to safely and practically build and manage a mechanism in a Windows environment ranging from the detection of unauthorized access and login failures to automatic webcam recording and email notifications. We will examine manual execution, folder structures, and limitations in order.
Objective and Overview of this Mechanism
According to primary sources, this tool (SecurityMonitor-PowerShell) is a system that monitors Windows security event logs, automatically starts webcam recording via FFmpeg when a login failure (Event ID 4625) is detected, and sends email alerts to multiple destinations.
The diagram below illustrates the processing flow from monitoring to recording as described in the primary sources.
flowchart TD
A[Windows Security Event Log] -->|Event ID 4625 detected| B(Threshold reached: 2 failed attempts in 30s)
B -->|Email alert sent| C[Gmail SMTP to multiple addresses]
B -->|Webcam recording starts| D[FFmpeg DirectShow]
D -->|Footage saved| E[C:\SecurityCam\footage\]
E --> F[Stop via Ctrl+Alt+S or stop.ps1]
Prerequisites, Warnings, and Requirements
When using and configuring this system, official information lists the following environment and preparatory steps.
OS: Windows 10 or Windows 11
Privileges: PowerShell must be run as an administrator
Tools: FFmpeg (obtained from the official website)
Notification Settings: Gmail account with two-factor authentication enabled and an app password
Devices: Built-in or external webcam
Additionally, the following limitations are noted in the primary sources.
It operates only while a user is logged in (PowerShell must be running).
Webcam cannot be accessed from the Windows login screen (OS-level restriction).
Webcam access via DirectShow requires a user session context.
Care must be taken when handling Gmail app passwords as they are stored within the script.
Folder Structure and File Layout
Official documentation requires files to be arranged in the following structure.
C:\SecurityCam\monitor.ps1: Main monitoring scripthotkey.ps1: Hotkey listener (for Ctrl+Alt+S)stop.ps1: Manual stop scriptfootage\: Destination directory for recorded video fileslogs\monitor.log: All event logsffmpeg_error.log: FFmpeg error output
Setup Procedure
The primary setup workflow based on official information is as follows.
Installing FFmpegDownload from the official build site and extract to the specified path. Consider the following command to verify the installation.
ffmpeg -version
Verifying Webcam NameRun the following command to check the video devices section in order to identify the exact device name to use.
ffmpeg -list_devices true -f dshow -i dummy 2>&1
monitor.ps1Configuring SettingsUpdate the following variables at the top of the script to match your environment.$gmailFrom: Sender email address$gmailPass: Gmail app password$alertTo1,$alertTo2: Alert destination address$webcam: Detected webcam name$ffmpegPath: FFmpeg executable path
Creating folders and deploying scriptsUse PowerShell to create the required directories.
New-Item -ItemType Directory -Force -Path C:\SecurityCam\footage New-Item -ItemType Directory -Force -Path C:\SecurityCam\logs
Operation and Usage
Since this is planned for verification in a Windows environment, the following procedures and output results are explanations based on primary source documentation.
To start monitoring, open PowerShell as an administrator, navigate to the working directory, temporarily change the execution policy, and launch the script.
cd C:\SecurityCam Set-ExecutionPolicy Bypass -Scope Process -Force .\monitor.ps1
If necessary, launch the hotkey listener in a separate window.
.\hotkey.ps1
To manually stop recording,stop.ps1execute the command, orhotkey.ps1press Ctrl+Alt+S while executing.
Example of Expected Console Output
The primary documentation provides the following example of console output upon successful operation.
Log at the start of monitoring (displaying threshold, lookback time, and polling interval)
Polling for failed login attempts within a specific period
Detection of "THRESHOLD HIT" when the threshold is reached (2 failures in 30 seconds), followed by email transmission and initiation of the recording process (displaying PID)
Email Alert Format
Emails sent when the threshold is exceeded include the detection time, computer name, account name, date, and storage path of the recording file to notify of potential unauthorized access.
Limitations and Future Improvements
The primary source also discusses the current system limitations and potential future improvements.
LimitationsRequires the user to be logged in and PowerShell to be running, and webcam access at the login screen is restricted due to OS-level limitations.
Planned Improvements:
Converting to a Windows service for pre-login monitoring
SMS alerts using Twilio
Email notification with attached video upon recording completion
Automatic startup via Task Scheduler upon login
Telegram bot notifications
Conclusion
This article outlines the components, setup, and operational procedures for a security monitoring system combining PowerShell, Windows Event Logs, and FFmpeg, based on the primary source.
The key prerequisites and constraints to check before execution are as follows:
PowerShell must be run with administrator privileges.
Gmail app passwords and webcam names must be verified in advance.
Due to Windows specifications, webcam recording at the login screen is not supported.
Operation has not been verified on physical hardware, so testing in each specific environment is required.

