Detect Free Tools
Deleted BAM Keys Parser
Analyses the registry, specifically for BAM (Background Activity Monitor) Key Deletions, and outputs found deleted, keys + if the file exists, its digital signature, and its entropy.
Windows Sqlite Database Parser
Analyze Windows database files for recent paths, executables, search history and notepad history. This only works on Windows 11 Machines.
BAM Parser
Parse and analyze BAM (Background Activity Moderator) data for timestamps, usn modifications and unsigned/flagged files with yara rules.
Prefetch Parser
Analyze Windows Prefetch files for unsigned, flagged files using yara and timestamps for execution.
PcaSvc Executed
Track and analyze Program Compatibility Assistant Service executions and flag unsigned files, and flagged files using yara rules.
Process Parser
Analyze AppInfo and Diagtrack for flagged files with yara rules, all in instance.