I'm using https://www.bitcoinvigil.com/ which is very slick but I may build my own equivalent of this at some point and shove the wallet.dat on all of my machines.
I can see this being useful as a canary to let you know someone has acquired unfettered access to your device, but it doesn't seem very practical for high value targets (who cares about $5 of bitcoin if there's far more valuable info to steal), or if the attacker decides to steal the bitcoin wallet file and only transfer coins a few weeks later after he's already taken advantage of the other info he got off the target device (and by then you probably already know you've been compromised anyway).
At best it's confirmation that you have been compromised, not evidence that you have not.