100EYES.WATCH - A WATCHTOWER, BUILT IN PUBLIC

MOST PEOPLE FIND OUT THEY WERE A TARGET AFTER IT'S TOO LATE.

I build and document ARGUS - an open-source guardian for the ordinary computer - and write about the scams and vulnerabilities people never see coming.

ARGUS · SKILL CONSTELLATION

The watch, star by star

built — opens the write-up · planned — opens the idea note

  • Gate-2 Classifier

    The millisecond malware/goodware verdict before execution. Three candidates compared on EMBER 2018 v2 — XGBoost leads at 97.78% validation accuracy; CNN and fusion pending.

  • Local LLM Tier

    A local model for the uncertain zone only. It renders and recommends — containment decisions are made by the deterministic layer and execute before inference runs.

  • Cloud Escalation

    Escalation only: cases the local tier cannot settle. Raw bytes never leave the machine — the privacy boundary holds regardless of tier.

  • RAG Threat Intel

    Two channels: exact-match hash/URL/IP lookups that lock a verdict instantly, and fuzzy semantic similarity used as evidence context for the LLM.

  • Sandbox

    The dynamic gate: detonate what static analysis cannot settle, watch what it actually does.

  • Tray App

    The quiet surface: verdicts and status without opening anything.

  • GUI

    The full instrument panel: incident history, verdicts, and the audit log, readable by a human.

MAIN QUEST · ARGUS

A quiet instrument panel for what is already built.

ARGUS is an open-source, local-first Windows security daemon built around quarantine-first containment across files, email, pip/npm packages, browser extensions, and clipboard.

Open the progress node ->
  • Filesbuilt
  • Emailbuilt
  • Packagesplanned
  • Browserplanned
  • Clipboardplanned

ARGUS LOG

Latest from the log