Detect Free Tools

BAM Parser

Parse and analyze BAM (Background Activity Moderator) data for timestamps, usn modifications and unsigned/flagged files with yara rules.

Prefetch Parser

Analyze Windows Prefetch files for unsigned, flagged files using yara and timestamps for execution.

PcaSvc Executed

Track and analyze Program Compatibility Assistant Service executions and flag unsigned files, and flagged files using yara rules.

Process Parser

Analyze AppInfo and Diagtrack for flagged files with yara rules, all in instance.