Endpoint Forensic Inspection Engine

175 forensic checks.
One command.
Minutes, not hours.

Your analysts spend 45–90 minutes per endpoint on manual forensic triage across 3–4 tools before the real investigation starts. Nova replaces all of it with a single agentless pass.

macOS Linux Windows No Agent No Internet No Installation
Request a 30-Day Trial See the Savings ↓
Your SOC spends $3,000–$15,000/month on manual triage.
Nova cuts that by 85–90%

Based on 20–50 investigations/week at $50/hr fully loaded analyst cost. Independently confirmed by SOC managers and incident response professionals.

45–90 min
Manual triage per endpoint
KAPE + Velociraptor + PowerShell + manual log correlation across separate passes
Under 10 min
With Nova — same endpoint
175 detection functions, single agentless pass, prioritized output with evidence
$36K–$180K
Annual labor savings per SOC
Analyst hours redirected from collection to actual investigation and response
15–75 hrs/week
Analyst time recovered
At 20–50 investigations/week, triage drops from 15–75 hrs to under 2 hrs weekly
Tool Displacement

Your analysts juggle 3–4 tools per endpoint.
Nova is one.

KAPE
Artifact collection
Velociraptor
Endpoint telemetry
PowerShell
Manual scripts
Manual Review
Log correlation
Nova 175
All of the above. One command. Minutes.
nova — endpoint inspection
$ python nova.py

[09:01:03] Nova 175 — starting full sweep
[09:01:03] Running module: env_secret_scanner
[09:01:05] Running module: persistence_mechanism_detector
[09:01:08] Running module: browser_credential_inspector
[09:01:11] Running module: cloud_credential_scanner
[09:01:14] Running module: lateral_movement_detector
[09:01:17] Running module: c2_communication_indicator
... 163 more modules

=== Nova 175 inspection complete ===
Total modules : 169
Completed : 169
Errors : 0

ALERT findings : 444
WARN findings : 9,203
INFO findings : 3,349

→ PDF report saved
→ JSON manifest saved (SIEM-ready)
175
Detection Functions
108
MITRE ATT&CK Techniques
22
Detection Families
3
Platforms
How It Works

One command replaces your entire manual triage workflow

Full sweep or targeted family execution — your analysts choose the scope.

⚠ Without Nova

  • Run KAPE for artifact collection
  • Run Velociraptor for endpoint telemetry
  • Run PowerShell scripts for credential checks
  • Manually correlate across 3–4 separate tools
  • 45–90 minutes before investigation starts
  • Inconsistent coverage across analysts
  • No standardized output format
  • Repeat for every endpoint, every investigation

✓ With Nova

  • One command: python nova.py
  • 175 detection functions in a single pass
  • All artifacts collected and correlated automatically
  • Prioritized findings with severity classification
  • Complete in minutes, not hours
  • Consistent coverage every time, every analyst
  • SIEM-ready JSON + human-readable PDF
  • MITRE ATT&CK mapped with evidence hashes
Flexible Execution

Full sweep or surgical precision

Run everything, or target exactly what you're investigating.

Mode A

Full Sweep

python nova.py

All 169 modules across 22 families. Comprehensive endpoint assessment, compliance audit, onboarding, or baseline scan.

Mode B

Family-Targeted

python nova.py --family credentials

Run only the modules in a specific family. Credential breach? Run Credentials + Browser. Post-malware? Run Persistence + Execution. Faster, targeted, less noise.

Detection Families

22 families. Full attack surface.

Each runs independently or as part of a full sweep. All output is MITRE ATT&CK mapped with deterministic severity classification.

Credentials

10 modules

Secrets, API keys, cloud creds, OAuth, SAML, MFA

Persistence

10 modules

Tasks, autostart, shell config, registry, services

Browser

8 modules

Extensions, credentials, phishing cache, storage

Cloud

8 modules

IAM, containers, logging gaps, metadata API

Process & Execution

10 modules

Hollowing, LOLBin, masquerading, injection

Malware & Payload

10 modules

Backdoors, C2, ransomware, rootkits, staging

Lateral Movement

6 modules

Credential reuse, Kerberos, pass-the-hash

Exfiltration

10 modules

Cloud, DNS, USB, C2 channel, email, HTTP

Code Injection

9 modules

DLL, shellcode, reflective, thread hijacking

Privilege Escalation

8 modules

Kernel, PATH hijack, sudo, token, SUID/SGID

System Integrity

11 modules

Audit logs, boot, config drift, patching

DNS & Reputation

7 modules

Anomalies, tunneling, poisoning, malicious DNS

Network

8 modules

Interfaces, shares, traffic, ports, proxy, VPN

Identity

6 modules

Accounts, auth logs, SSH, sudo, password policy

AppSec

10 modules

Web security, API, auth bypass, crypto weakness

Advanced Threat

6 modules

APT indicators, behavioral anomaly, EDR tamper

AD & Identity

5 modules

AD enum, Kerberoasting, credential dumping

Containers

6 modules

Escape, image integrity, K8s RBAC, secrets

Vulnerability

7 modules

Compliance, risk scoring, supply chain, zero-day

Certificates

5 modules

Pinning, transparency, expired, root CA

Wireless & VPN

4 modules

Wireless scan, VPN security, port detection

USB & Removable

5 modules

USB monitor, media policy, DLP, encryption

Getting Started

Try Nova for 30 days

No payment. No commitment. Run it on your endpoints. Judge the output yourself.

1

Request access

Tell us your platform and what you're investigating. We send you the trial build.

2

Run Nova

One command. Full sweep or targeted families. No agent, no internet, no installation.

3

Review the output

Prioritized findings with MITRE ATT&CK mapping, severity classification, evidence hashes, and SIEM-ready JSON.

4

If it saves time, we talk

After 30 days, if Nova is useful, we discuss licensing. If not, it expires automatically. No obligations.

See what Nova finds.

Request a 30-day trial or a sample findings report from a real endpoint scan.

Request a 30-Day Trial Request Sample Report