note Yale Herbert Scarf Award Winner

Access the evidence already on every endpoint.

Have we already been compromised? TensorGuard finds out — with evidence.

Answer all of these questions — with evidence. Built on award-winning research, TensorGuard analyzes the forensic artifacts every endpoint already records and delivers fleet-wide results in minutes, not weeks. Every finding is linked to the raw artifact it came from. We don't replace your EDR, we give it a memory.

  • Evidence-Backed Answers
  • First Reporting in ~15 Min
  • Proactive, Not Reactive
  • Deep Analysis, Plain Language
TensorGuard Console
Compromise Assessment
Result: Positive
CRITICAL
T1078 · Valid AccountsT1005 · Data from Local SystemT1021 · Remote Services

Artifacts indicate the previous owner's account is still signing in — this device was reassigned eight months ago, yet the old account logs on remotely every week, browsing finance directories and syncing files to personal cloud storage.

Evidence thread · Access After Departure
ProfileList device reassigned; new primary user 8 months ago
EVTX previous owner's account logs on weekly since
ShellBags finance & HR directories browsed interactively
Browser personal cloud storage visited every session
SRUM gigabytes uploaded on each visit
EVTX 30%
ProfileList 20%
ShellBags 20%
Browser 15%
SRUM 15%
18 artifact types processed · 4.1B entries reviewed
TensorGuard Console
Insider Risk Assessment
Result: Positive
CRITICAL
T1560 · Archive Collected DataT1052 · Exfil Over PhysicalT1070 · Indicator RemovalT1567 · Exfil Over Web Service

Immediately after receiving a Performance Improvement Plan, the user staged 3.3 GB of corporate data and exfiltrated it via Microsoft Edge and a personal USB device.

Evidence thread · Data Exfiltration
$MFT Archive.zip staged on Desktop · 3,300,150,120 bytes
SRUM msedge.exe transmitted exactly 3,300,150,120 bytes
AmCache SanDisk 3.2 Gen1 USB connected same hour
Browser searched “how to permanently delete files” after copy
Browser personal OneDrive account accessed at 03:52
AmCache 40%
Browser 25%
SRUM 20%
$MFT 15%
17 artifact types processed · 3.8B entries reviewed
TensorGuard Console
Offboarding Sweep
Result: Positive
CRITICAL
T1074 · Data StagedT1567 · Exfil Over Web ServiceT1537 · Transfer to Cloud

In their final week, artifacts indicate the user installed a personal Dropbox client, copied 4,100 work files into its sync folder, and browsed project directories they had never opened in two years.

Evidence thread · Final-Week Collection
AmCache dropbox.exe installed 6 days before departure
USN Journal 4,102 files copied into the sync folder in one afternoon
ShellBags first-time browsing of engineering & finance shares
SRUM 3.9 GB uploaded by dropbox.exe that week
Browser personal webmail open every day of the final week
USN Journal 25%
AmCache 25%
SRUM 20%
ShellBags 20%
Browser 10%
17 artifact types processed · 3.6B entries reviewed
TensorGuard Console
Due Diligence Assessment
Result: Negative
MODERATE
T1552 · Unsecured CredentialsT1562 · Impair DefensesT1219 · Remote Access Tools

No indications of active external compromise — but significant hygiene liabilities on this machine: plaintext SSH keys in user directories, unmanaged remote access, and peer-to-peer applications.

Evidence thread · Security Hygiene Liabilities
$MFT plaintext SSH private keys in user directories
$MFT passwords.xlsx saved in Downloads
EVTX Windows Defender disabled to run custom tool
AmCache vendor support tool from a one-time session, still running 14 months later
ProfileList 3 dormant service accounts, last logins 3 years ago
$MFT 35%
EVTX 25%
AmCache 20%
ProfileList 20%
19 artifact types processed · 5.1B entries reviewed
TensorGuard Console
Compromise Assessment
Result: Positive
CRITICAL
T1219 · Remote Access ToolsT1053 · Scheduled TaskT1543 · System Process

Evidence indicates a covert outbound tunnel has been running on this workstation for 217 days — installed months before the current EDR was deployed, and never alerted on.

Evidence thread · Dormant Since Before Deployment
$MFT tunnel binary written 217 days ago
Scheduled reconnects the tunnel on every logon to https://...
SRUM steady outbound traffic every day since
USN Journal tunnel config rotated last week — still maintained
EVTX predates current EDR install by 4 months
SRUM 35%
$MFT 20%
EVTX 15%
Scheduled 15%
USN Journal 15%
18 artifact types processed · 4.6B entries reviewed
TensorGuard Console
Insider Risk Assessment
Result: Positive
CRITICAL
T1070 · Indicator RemovalT1036 · MasqueradingT1485 · Data Destruction

After exfiltrating the staged archive, artifacts indicate the user researched secure deletion, wiped the files, and timestomped their $MFT records to the Unix epoch — a deliberate attempt to destroy evidence.

Evidence thread · Anti-Forensics Activity
Browser searched “how to copy files without being detected”
$MFT Archive.zip timestamps reset to 1970-01-01
AmCache secure-erase tool (sdelete.exe) run twice
USN Journal deletion sequence reconstructed despite wiping
EVTX 14-minute logging gap during the wipe window
$MFT 35%
Browser 25%
USN Journal 20%
AmCache 10%
EVTX 10%
17 artifact types processed · 3.9B entries reviewed
TensorGuard Console · Data Exfiltration

The staged 3.3 GB archive left this workstation through two channels within the same hour.

SRUM msedge.exe transmitted exactly 3,300,150,120 bytes — matching the size of the staged Archive.zip.
AmCache SanDisk 3.2 Gen1 USB device connected at 19:01, coinciding with the staging window.
Browser user logged into a personal OneDrive account at 03:52 — a potential cloud exfiltration channel.
AmCache 50%
Browser 25%
SRUM 25%
Source: [ID0142:Srum:SRUM_Network:88231]
TensorGuard Console · Data Staging & Compression

Immediately upon receiving a Performance Improvement Plan, the user compressed 3.3 GB of corporate data onto the Desktop.

ShimCache 7-Zip utility (7z.exe) executed at 19:01.
$MFT Archive.zip created on Desktop — 3,300,150,120 bytes, 0x30 creation timestamp.
AmCache 7z.exe presence and execution confirmed, last-write timestamp matches.
$MFT 50%
ShimCache 25%
AmCache 25%
Source: [ID0207:Mft:$MFT:$MFT_Output:33515]
TensorGuard Console · Anti-Forensics Activity

Following the exfiltration, the user researched secure deletion and attempted to destroy the evidence trail.

Browser extensive research on secure file deletion and undetected file copying.
$MFT staged files deleted; MFT records timestomped to the Unix epoch (1970-01-01).
USN Journal full deletion sequence reconstructed from journal entries the wipe missed.
$MFT 45%
Browser 30%
USN Journal 25%
Source: [ID0193:Mft:$MFT:$MFT_Output:33510]
TensorGuard Console · Weekly Fleet Assessment
1,000 endpoints · weekly sweep 2 flagged
DESKTOP-SJENKINS CRITICAL
3.3 GB staged via 7-Zip, exfiltrated via Edge + USB
$MFT · AmCache · SRUM
WS-1187 MODERATE
Three unmanaged remote access tools running
$MFT · ShimCache · EVTX

The average US breach goes undetected for 277 days.

TensorGuard closes that gap in minutes — with evidence. Stop reacting to breaches. Start finding them first.

~94%
lower analysis cost
~15 min
to first reporting
25+
artifact types parsed
100%
evidence-linked findings

‡ IBM Cost of a Data Breach Report, 2023.

How it works

From endpoint to evidence in three steps

Deep analysis in plain language. Every AI-generated finding links back to the raw artifact it came from.

01

Deploy in minutes

A lightweight Windows agent rolls out fleet-wide silently — no reboots, no user disruption, cloud or on-prem.

02

Collect automatically

$MFT, AmCache, SRUM, EVTX, ShellBags and more are parsed and preserved on a schedule you set — before you need them.

03

Read the evidence

Our analysis engine turns artifacts into plain-English findings, timelines and remediation steps — every claim linked to raw evidence.

Forensic collection as a service.

Move beyond the limits of manual investigations. Deploy our lightweight agent to schedule and automate forensic collections across your entire fleet, from servers to endpoints, ensuring you always have a baseline of evidence.

  • Unlimited Scale
  • Secure Archival
  • Automated Collection
  • Online/Offline
Get Started Now
feature-image feature-image

Analysis powered by artificial intelligence.

Our contextual analysis engine—powered by modern AI and proven statistical methods—sifts through gigabytes of artifacts in minutes. We don't give you a data dump; we give you answers.

  • Executive Summary
  • Remediation Steps
  • IoC Timeline
  • Raw Evidence
Get Started Now
feature-image feature-image

Unified reporting and intervention.

Access and manage findings through an intuitive web platform. Every AI-generated insight is directly linked to its underlying forensic proof, giving you absolute confidence to act.

  • Web/Native
  • Device Actions
  • Case Workflows
  • User Management
Get Started Now
feature-image feature-image

and, much more

A full spectrum of advanced forensic capabilities, making deep historical analysis and proactive threat hunting an accessible, continuous process for organizations of any scale.

icon

Deep Historical Insight

Access years of forensic data, even predating TensorGuard's installation, to uncover long-dormant threats and reconstruct past device activities.

icon

Intuitive Indicator Views

Empower your team with TensorGuard's 'Indicators' that translate complex forensic data into easily understandable events, no deep forensic expertise required.

icon

Unlimited Endpoint Scaling

Establish a comprehensive forensic baseline across your entire device fleet, moving beyond the cost-prohibitive limitations of per-device consulting hours.

icon

EDR Complementation

Enhance your existing EDR by filling the historical data gap, creating a complete security posture that fuses live prevention with strong forensic truth.

icon

Proactive & Continuous Monitoring

Schedule intelligent reporting to automatically hunt for threats using digital forensics as a novel data source, continuously identifying risks before they become incidents.

icon

Targeted Activity Search

Instantly query your entire fleet for specific activity. Answer critical questions like, "Has this malicious tool ever run on any of our servers?" in seconds with directly cited forensic evidence.

Forensic Integrations

Explore the Windows forensic artifacts TensorGuard collects and analyzes at fleet scale — $MFT, AmCache, SRUM, PowerShell history, Microsoft 365, and more.

Explore All Artifacts
AmCache

AmCache

BAM/DAM

BAM/DAM

Event Logs

Event Logs

Jumplists

Jumplists

MFT

MFT

Microsoft 365

Microsoft 365

Network List

Network List

Prefetch

Prefetch

Profile Lists

Profile Lists

PS History

PS History

RDP Client

RDP Client

Recent Lnks

Recent Lnks

Recycle Bin

Recycle Bin

Scheduled Tasks

Scheduled Tasks

Services

Services

Shell Bags

Shell Bags

ShimCache

ShimCache

Slack

Slack

SRUM

SRUM

Startup Tasks

Startup Tasks

User MRU

User MRU

UserAssist

UserAssist

USN Journal

USN Journal

Web Browser

Web Browser

AmCache

AmCache

BAM/DAM

BAM/DAM

Event Logs

Event Logs

Jumplists

Jumplists

MFT

MFT

Microsoft 365

Microsoft 365

Network List

Network List

Prefetch

Prefetch

Profile Lists

Profile Lists

PS History

PS History

RDP Client

RDP Client

Recent Lnks

Recent Lnks

Recycle Bin

Recycle Bin

Scheduled Tasks

Scheduled Tasks

Services

Services

Shell Bags

Shell Bags

ShimCache

ShimCache

Slack

Slack

SRUM

SRUM

Startup Tasks

Startup Tasks

User MRU

User MRU

UserAssist

UserAssist

USN Journal

USN Journal

Web Browser

Web Browser

Start with a Compromise Assessment.

One flat fee, fully credited toward a subscription. We conduct a complete, AI-driven Compromise Assessment across your critical systems — with evidence-linked findings your team can validate in minutes.

TensorGuard Automated DFIR Platform Dashboard