Your analysts spend 45–90 minutes per endpoint on manual forensic triage across 3–4 tools before the real investigation starts. Nova replaces all of it with a single agentless pass.
Based on 20–50 investigations/week at $50/hr fully loaded analyst cost. Independently confirmed by SOC managers and incident response professionals.
Full sweep or targeted family execution — your analysts choose the scope.
Run everything, or target exactly what you're investigating.
python nova.py
All 169 modules across 22 families. Comprehensive endpoint assessment, compliance audit, onboarding, or baseline scan.
python nova.py --family credentials
Run only the modules in a specific family. Credential breach? Run Credentials + Browser. Post-malware? Run Persistence + Execution. Faster, targeted, less noise.
Each runs independently or as part of a full sweep. All output is MITRE ATT&CK mapped with deterministic severity classification.
Secrets, API keys, cloud creds, OAuth, SAML, MFA
Tasks, autostart, shell config, registry, services
Extensions, credentials, phishing cache, storage
IAM, containers, logging gaps, metadata API
Hollowing, LOLBin, masquerading, injection
Backdoors, C2, ransomware, rootkits, staging
Credential reuse, Kerberos, pass-the-hash
Cloud, DNS, USB, C2 channel, email, HTTP
DLL, shellcode, reflective, thread hijacking
Kernel, PATH hijack, sudo, token, SUID/SGID
Audit logs, boot, config drift, patching
Anomalies, tunneling, poisoning, malicious DNS
Interfaces, shares, traffic, ports, proxy, VPN
Accounts, auth logs, SSH, sudo, password policy
Web security, API, auth bypass, crypto weakness
APT indicators, behavioral anomaly, EDR tamper
AD enum, Kerberoasting, credential dumping
Escape, image integrity, K8s RBAC, secrets
Compliance, risk scoring, supply chain, zero-day
Pinning, transparency, expired, root CA
Wireless scan, VPN security, port detection
USB monitor, media policy, DLP, encryption
No payment. No commitment. Run it on your endpoints. Judge the output yourself.
Tell us your platform and what you're investigating. We send you the trial build.
One command. Full sweep or targeted families. No agent, no internet, no installation.
Prioritized findings with MITRE ATT&CK mapping, severity classification, evidence hashes, and SIEM-ready JSON.
After 30 days, if Nova is useful, we discuss licensing. If not, it expires automatically. No obligations.
Request a 30-day trial or a sample findings report from a real endpoint scan.