Endpoint user activity monitoring on Windows
The Windows Client is the Syteca agent that runs on Windows workstations and servers to record what users actually do - screen activity, applications opened, websites visited, keystrokes (including in RDP and terminal-services sessions), files transferred, USB devices used. The data streams to the Syteca Application Server in real time, where security and HR teams replay it as video, search it, and feed it into the alerting engine. If you’ve been wrestling with insider-risk visibility on Windows endpoints, this is the layer that closes the gap. It captures what SIEM, EDR, and DLP miss: the human context behind an alert - exactly who did what, on which window, at which moment.Use the Windows Client when you need to:
- Record user sessions on Windows desktops, servers, RDP hosts, Citrix, and Terminal Services environments.
- Investigate insider threats with video-quality replay of what a user actually saw and did.
- Monitor multiple concurrent sessions on a single Windows Server (depending on endpoint license type).
- Capture keystrokes and screen activity to satisfy compliance audits (PCI DSS, HIPAA, SOC 2).
- Deploy at scale - silently via MSI/GPO/Intune - across thousands of Windows endpoints.
For installation, configuration parameters, and uninstallation, see the dedicated pages under this section.
How a Windows Client operates
- Starts automatically with the computer.
- Monitors local and remote sessions, including multiple concurrent sessions, depending on the endpoint license type.
- Records a new session every login (and every restart). The maximum duration of one session is 24 hours - all live sessions terminate at midnight, change from Live to Finished, and new live sessions start automatically.
- Records all monitors if the user has multiple displays connected.
- Compresses monitoring data on the Client side before sending it to the Application Server.
- Self-heals. If a Client ever stops working, the EkranController watchdog process restarts it automatically.
Windows Clients use AES-256 encryption to exchange binary data with the Application Server.
Offline behavior
If the Client loses connection to the Application Server, it temporarily stores monitoring data locally in a file namedTempWrite.dat inside the Client installation folder. As soon as the connection is restored, the cached data is sent automatically.
The Client stops writing to the offline cache in either case:
- The cached size reaches the offline cache limit set during remote installation or installation package generation. The default is 500 MB.
- The drive has less than 500 MB of free space.
Recording frequency
By default, the Windows Client records user activity at these intervals (averaged - see the note below):Recording triggers influence each other, so the average frequency is usually lower than the defaults above. The Client never records more often than these values.
Adjust the typing or mouse-clicking frequency
To change the default recording frequency, edit the Windows Registry on the Client computer at:Disable data compression
Compression is on by default. To disable it, add a new value at the same registry key:Read the Client status
A Windows Client’s status in the Clients page tells you whether it’s up to date.Up-to-date Client
If automatic update is enabled, the Client updates itself as soon as it connects to a newer Application Server. Up-to-date Clients show a green checkmark in the Client Version column.Not-up-to-date Client
If the Update Client automatically checkbox is not selected for a Client, it must be updated manually. Such Clients appear with:Clients that aren’t up to date continue to monitor user activity and send data to the Application Server as normal. After an update, the monitored data recorded before the update remains accessible.

The Clients page showing a Windows Client that requires a manual update.
Related
Editing the Windows Client Configuration
A tab-by-tab map of every setting on the Editing Client page.
Update Clients
Automatic and manual update procedures for any OS.
macOS Clients
The macOS equivalent - local and remote session monitoring.
Linux Clients
Terminal, SSH, and GUI monitoring on Linux.
System Health dashboards
Online / Offline / Disconnected Client counts.