The TensorGuard Platform

How it works.

Four components, one direction of travel: evidence flows from every endpoint to an answer your whole team can validate. No kernel drivers, no data pool, no black box.

01
Agent
Read-only collection on every endpoint
02
Artifacts
25+ forensic datasets per device
03
Analysis
Semantic analysis at fleet scale
04
Console
Reports, artifacts, and remediation in one console.

01 · Agent

A collector, not a watcher.

The TensorGuard agent does one thing: read the forensic datasets the operating system already records, and package them for analysis. It watches nothing, intercepts nothing, and installs nothing at the kernel level — which is why it deploys like software, not like a security project.

  • Read-only by design — no kernel drivers, no behavioral monitoring
  • No data pool or data lake to build, secure, or feed
  • Fleet-wide silent deployment in minutes, no reboots
  • Point-in-time .spade packages — collect now, analyze later
collector — spec
Mode
read-only forensic collection
Kernel
never touched — no drivers installed
Platform
Windows endpoints & servers
Output
signed .spade evidence packages

02 · Artifacts

The ground truth, already recorded.

Every Windows endpoint continuously writes its own history — years of it, predating installation. TensorGuard parses that history into structured, queryable evidence across more than 25 artifact types, and preserves it before logs rotate or devices are recycled.

  • Filesystem: $MFT, USN Journal, LogFile, INDX
  • Execution: AmCache, ShimCache, Prefetch, UserAssist
  • Activity: SRUM, EVTX, ShellBags, JumpLists, browser history
  • Cloud: Microsoft 365 audit logs, Slack

03 · Analysis

True correlation, not signatures.

Signature detection fails against novel attacks; anomaly heuristics fail to explain themselves. Our analysis engine takes a third path: it understands what an analyst is looking for, validates candidate evidence programmatically, and hoists corroborated data points into findings — so combinations of individually-innocent events surface, and every conclusion can be traced back down.

  • Findings flag what signature tools structurally cannot see
  • Programmatic validation reduces hallucination by design
  • Correlated timelines across millions of events per device
  • Typical fleet sweep: first reporting in ~15 minutes

04 · Console

Decoded evidence, not just answers.

The Console turns analysis into assessment reports: a verdict up front, a plain-English summary, and an evidence thread behind every claim — each citation one click from the raw artifact it rests on. Browse the decoded artifacts directly, with or without the analysis. Act directly with one-click remediations, in the web console or the native Windows and Linux app.

  • Verdicts with severity, MITRE ATT&CK mapping, BLUF summaries
  • Evidence threads with per-artifact citations and timelines
  • One-click remediations with reviewable scripts
  • Web console plus native Windows and Linux client

Deployment

Run it where your evidence lives.

Same platform, two operating models — either way, your forensic evidence stays under your control, with FIPS-aligned chain of custody on every collection.

Cloud

Fully managed by TensorGuard. The fastest path from signup to first sweep.

On-Prem

The entire platform inside your infrastructure. Nothing leaves your environment.

Join the future of forensics.

Start with a flat-fee Compromise Assessment — fully credited toward a subscription.

Book a Demo