Windows guide
Same tool, same commands. A few notes.
Install
pip install sentinel-watch
sentinel doctor $HOME
Needs Python 3.10+. No compiler, no drivers. watchdog, psutil, all wheels.
Popups work out of the box with a plain message box. Richer toasts need plyer:
pip install plyer
Always on
--daemon fork is unix only. Pick per OS:
sentinel service /home/you/Documents --install
Prints systemd steps on Linux, launchd steps on Mac, and points at win-task --create on Windows. Units live in examples/.
sentinel win-task C:\Users\you\Documents --create
Shows the exact schtasks line first. Creates an ONLOGON task at HIGHEST run level running sentinel watch --response auto. Remove with --remove. Task name defaults to SentinelWatch, change with yaml win_task:.
What is checked
- Run keys
HKCU\...\RunandRunOnceviasentinel persist - Startup folder lnks and exes
- Odd connections via
sentinel netscan - Canaries, burst, entropy, notes via
sentinel watch
Registry reads need nothing special for HKCU. HIGHEST task level covers protected spots.
Response tiers
Same as unix: warn, auto, paranoid. On Windows kill uses terminate, hold uses psutil suspend which freezes the proc until quar --resume-pid.
sentinel watch C:\Data --response auto --notify
Paths
Quote them. Backslashes are fine:
sentinel init "C:\Users\you\Documents"
sentinel check "C:\Data" --json
Note names match case blind, entropy skips zips and pics by magic bytes same as unix.
Limits
- No kernel driver, so no boot time or kernel rootkit view
- SmartScreen and Defender stay on, sentinel sits next to them
- Long paths over 260 chars need long path support on in Windows