Detect Free Tools

Deleted BAM Keys Parser

Analyses the registry, specifically for BAM (Background Activity Monitor) Key Deletions, and outputs found deleted, keys + if the file exists, its digital signature, and its entropy.

Windows Sqlite Database Parser

Analyze Windows database files for recent paths, executables, search history and notepad history. This only works on Windows 11 Machines.

BAM Parser

Parse and analyze BAM (Background Activity Moderator) data for timestamps, usn modifications and unsigned/flagged files with yara rules.

Prefetch Parser

Analyze Windows Prefetch files for unsigned, flagged files using yara and timestamps for execution.

PcaSvc Executed

Track and analyze Program Compatibility Assistant Service executions and flag unsigned files, and flagged files using yara rules.

Process Parser

Analyze AppInfo and Diagtrack for flagged files with yara rules, all in instance.