SOC teams typically rely on several separate tools and manual review to investigate an endpoint. Nova consolidates that process into a single tool that produces one structured report — filtered to real findings, not raw noise.
Endpoint investigation typically means moving between several separate tools, then manually correlating what each one finds. Nova runs as a single tool and produces one report — reducing the number of tools involved and the manual work required to get from raw artifacts to a usable finding.
Collection is only half the problem. Nova applies an extensive filtering layer on top of what it collects — a deterministic classification system with named, auditable rules and a built-in allowlist for expected, known-safe artifacts — so the report an analyst opens is focused on real findings, not a raw dump of everything the scan touched.
Alongside the readable report, Nova also prints a structured JSON file — a full receipt of every finding the scan produced, with nothing summarized away. It's the underlying record the report is built from, kept for reference, audit, or downstream use.
The filtering layer above measurably reduces raw findings down to a classified, prioritized set — roughly a 90% reduction from unfiltered output to what actually reaches the report.
Time and labor savings depend on what's being replaced: teams moving off a largely manual, ad-hoc process tend to see reductions toward the higher end (~85–90%); teams already running partial automation and reconciling multiple tools by hand tend to see reductions toward the lower end (~50–70%). As a range, roughly 70–90%, depending on the toolchain being replaced.
Fewer separate tools required for endpoint investigation work.
Less manual correlation between tools means less analyst time per investigation.
Findings are collected and organized automatically rather than assembled by hand.
A single report replaces a multi-step, multi-tool manual process.
Detection spans 22 families. Two representative examples are shown below — the full list is available on request.
Exposed secrets, API keys, and credential material left in configuration and storage locations.
Mechanisms that allow code or access to survive a reboot or session change.
+ 20 more families
Full list available on request
No. Nova isn't a replacement for continuous monitoring — it's the forensic layer that runs after an alert fires, doing the artifact collection and correlation an analyst would otherwise do by hand.
Output is structured for direct use in downstream tooling. Several practitioners have used it as a triage step feeding into existing incident response workflows.
Findings run through a deterministic, tiered classification system with named, auditable rules — not a black-box score. Known-safe and expected artifacts are filtered out through a built-in allowlist, so what reaches the report is focused on real findings rather than routine noise.
Each detection module is implemented natively per platform rather than generically. Cross-platform parity is a core design requirement.
This page is for information only. For a technical report, a live test, or further information, reach out directly.