Some screen privacy tools market themselves as "undetectable." This is a dangerous claim. It implies that the tool leaves no trace, that no observer can know it is running, and that protection is absolute. None of these implications are true. And when users discover the truth, the trust they placed in the tool evaporates.
Here is the honest reality of what is and is not detectable about screen privacy tools.
What "Undetectable" Usually Means in Marketing
When a tool claims to be undetectable, it typically means one of three things:
- The cloaked window is not visible in screen captures. This is true for supported capture APIs. It is not true for all capture methods.
- The tool does not appear in the taskbar or system tray. This is a UI choice, not a security feature. Task Manager still shows the process.
- The tool does not trigger antivirus alerts. This depends on the antivirus and the tool's behavior. It is not a property of the tool itself.
None of these mean "undetectable" in any meaningful security sense.
What Is Actually Detectable
Process enumeration. NoCapture, Evanesco, CaptureGuard, WinHider, and Cloakly all run as user-mode processes. Any user with task manager or tasklist can see them. EDR tools flag them automatically.
DLL injection traces. Tools that inject into target processes leave module lists that can be enumerated. CaptureGuard documents this explicitly. NoCapture does the same.
Window property changes. WDA_EXCLUDEFROMCAPTURE modifies window properties. Tools that query window affinity can detect the flag.
Network activity. If the tool checks for updates or syncs policies, it generates network traffic. Firewalls see it.
Behavioral signatures. A window that is visible to the user but black in screenshots is itself a signature. An observer who sees a black rectangle where content should be knows that cloaking is active.
Why This Matters
A user who believes their tool is "undetectable" may take risks they would not otherwise take. They may share more sensitive information. They may assume protection extends to employer monitoring or forensic analysis. When they discover that the tool is visible to EDR, logged by IT, or detectable through behavioral analysis, they feel deceived.
We believe the opposite approach is more valuable: tell users exactly what is detectable, exactly what is not, and let them make informed decisions.
What NoCapture Actually Claims
NoCapture does not claim to be undetectable. We claim:
- Cloaked windows are invisible to supported software capture APIs
- Title masking sanitizes metadata in taskbar and Alt-Tab
- Notification shield suppresses banners from protected apps
- Live preview lets you verify the capture stream
- Routines and Focus Mode automate protection
All of these are verifiable. None of them imply invisibility to system administrators, forensic tools, or physical observation.
We wrote about the honest limitations of WDA-based tools here.
How to Evaluate "Undetectable" Claims
When you see this phrase, ask three questions:
- Undetectable by what? Screen capture tools? Process monitors? Forensic analysis?
- Detectable by whom? The user? The IT admin? A kernel-level tool?
- What is the evidence? Has the vendor published detection tests?
If the answers are vague, the claim is marketing, not engineering.
The Bottom Line
Every screen privacy tool is detectable by something. The honest vendors tell you what that something is. The dishonest ones imply invisibility. NoCapture chooses honesty because trust is more valuable than a catchy tagline.
Your screen privacy tool should protect you against the threats you actually face: accidental leaks during Zoom calls, notification banners, metadata exposure. It should not pretend to protect you against threats it cannot stop: kernel forensics, physical cameras, or determined system administrators.
Know the difference. Choose accordingly.
NoCapture provides OS-level window cloaking, title masking, and notification shielding for Windows. Free for two windows. Because "being careful" isn't a strategy.


