Endpoint Forensic Inspection

Multiple tools. Manual work.
One report, instead.

SOC teams typically rely on several separate tools and manual review to investigate an endpoint. Nova consolidates that process into a single tool that produces one structured report — filtered to real findings, not raw noise.

Get in Touch See How It Works ↓
What Nova Does

Consolidation, not another tool to manage

Endpoint investigation typically means moving between several separate tools, then manually correlating what each one finds. Nova runs as a single tool and produces one report — reducing the number of tools involved and the manual work required to get from raw artifacts to a usable finding.

Collection is only half the problem. Nova applies an extensive filtering layer on top of what it collects — a deterministic classification system with named, auditable rules and a built-in allowlist for expected, known-safe artifacts — so the report an analyst opens is focused on real findings, not a raw dump of everything the scan touched.

Alongside the readable report, Nova also prints a structured JSON file — a full receipt of every finding the scan produced, with nothing summarized away. It's the underlying record the report is built from, kept for reference, audit, or downstream use.

Reduction, in Practice

The filtering layer above measurably reduces raw findings down to a classified, prioritized set — roughly a 90% reduction from unfiltered output to what actually reaches the report.

Time and labor savings depend on what's being replaced: teams moving off a largely manual, ad-hoc process tend to see reductions toward the higher end (~85–90%); teams already running partial automation and reconciling multiple tools by hand tend to see reductions toward the lower end (~50–70%). As a range, roughly 70–90%, depending on the toolchain being replaced.

Tooling Cost

Fewer separate tools required for endpoint investigation work.

Analyst Cost

Less manual correlation between tools means less analyst time per investigation.

Manual Cost

Findings are collected and organized automatically rather than assembled by hand.

Time / Labor

A single report replaces a multi-step, multi-tool manual process.

Consolidation

Instead of separate tools per task, one pass.

Artifact Collection
Separate tool
Endpoint Telemetry
Separate tool
Manual Scripts
Separate process
Manual Review
Separate process
Nova
One tool. One report.
169
Detection Modules
22
Detection Families
3
Platforms
Coverage

A sample of what's covered

Detection spans 22 families. Two representative examples are shown below — the full list is available on request.

Credentials

Exposed secrets, API keys, and credential material left in configuration and storage locations.

Persistence

Mechanisms that allow code or access to survive a reboot or session change.

+ 20 more families
Full list available on request

Common Questions

Before you ask

?

Does Nova replace our EDR/XDR?

No. Nova isn't a replacement for continuous monitoring — it's the forensic layer that runs after an alert fires, doing the artifact collection and correlation an analyst would otherwise do by hand.

?

How does Nova fit into our existing workflow?

Output is structured for direct use in downstream tooling. Several practitioners have used it as a triage step feeding into existing incident response workflows.

?

How are findings prioritized?

Findings run through a deterministic, tiered classification system with named, auditable rules — not a black-box score. Known-safe and expected artifacts are filtered out through a built-in allowlist, so what reaches the report is focused on real findings rather than routine noise.

?

Is coverage consistent across macOS, Linux, and Windows?

Each detection module is implemented natively per platform rather than generically. Cross-platform parity is a core design requirement.

By Inquiry Only

Interested in a report, or in testing?

This page is for information only. For a technical report, a live test, or further information, reach out directly.

Inquire