Local Windows audit

Latch

Defender, firewall, updates, logons, startup commands, and scheduled tasks are read on your PC. This page cannot see them, so it does not invent a status. Latch used to be called Security Sentinel.

Download Latch.ps1Weekly taskNo account

Automation

Right-click PowerShell, Run as administrator. -InstallWeekly registers a task named Latch for Sunday at 09:00 while you are signed in. That job writes an HTML report and a JSON summary to your Desktop. It does not prompt for a password and it does not call the breach API.

powershell -ExecutionPolicy Bypass -File .\Latch.ps1 -FullScan
powershell -ExecutionPolicy Bypass -File .\Latch.ps1 -CheckPasswords
powershell -ExecutionPolicy Bypass -File .\Latch.ps1 -InstallWeekly
powershell -ExecutionPolicy Bypass -File .\Latch.ps1 -RemoveWeekly
  • Defender, firewall, hotfixes, failed logons, and outside-LAN successes.
  • Startup Run and RunOnce values. Temp, Downloads, and encoded PowerShell are marked Review.
  • Non-Microsoft scheduled tasks registered in the last 14 days, plus risky commands.
  • -RemoveWeekly deletes the Latch task, and the older BlackBoxLatch name if it is still installed.
  • -CheckPasswords is manual. -PasswordToCheck lands in shell history.

Breach check, live

The password is hashed in this browser. Only the first 5 characters of the SHA-1 are sent to the Have I Been Pwned range API. The field clears as soon as you check. A clean result is not proof the password is strong.

Hygiene

0 of 9 marked on this browser. Stored locally, not on a server.