Forensics. Decode. Truth.
When enterprises get hacked, they call a DFIR firm. You shouldn't need a $50,000 retainer to find out if someone's been on your machine.
You probably won't find out you've been hacked.
Antivirus is built for known malware. Sophisticated attackers don't use known malware. They live in your processes, your scheduled tasks, your registry. Invisible to consumer tooling.
Average attacker dwell time before detection.
Of advanced threats missed by traditional antivirus.
Typical DFIR firm engagement to investigate one incident.
Three scan depths. One platform.
Pick the depth you need, pay per scan. From a quick health check to a full forensic investigation.
Surface Sweep
Quick health check. Catches obvious threats fast.
- Running processes & connections
- Active persistence items
- DNS cache snapshot
- Startup entries
Behavioral Analysis
Broader behavioral signal. Catches stealthier threats.
- Full process tree
- Scheduled tasks & cron
- Registry run keys
- Browser extension audit
- 7-day event log review
Full Investigation
Forensic-grade. The same depth a DFIR firm would charge $50k for.
- Complete filesystem timeline
- MFT & shellbag analysis
- WMI subscription audit
- IOC enrichment (VT + AbuseIPDB)
- MITRE ATT&CK mapping
- Full attack reconstruction
From signup to forensic clarity in under an hour.
Create your account
Sign up and verify your email. We never ask for credit cards before your first scan.
Install the agent
Lightweight desktop agent for Windows, macOS, and Linux. Sits in your system tray. Enrolls in one click.
Run a scan
Pick Standard, Medium, or Deep. Pay only for what you run. Real-time progress in the dashboard.
Read your report
Risk score, plain-English findings, attack timeline, MITRE ATT&CK map, and a prioritized action plan.
Built for forensic clarity, not security theater.
Local-First
Telemetry is collected and analyzed on your own device. Your forensic data never leaves your hardware without consent.
Forensic Depth
MFT, shellbags, WMI subscriptions, registry timelines. The same artifacts a DFIR firm pulls in week-long engagements.
AI Reports
AI translates raw forensic artifacts into plain English. What it means, why it matters, what to do next.
Every finding mapped to a real attacker technique.
Findings are tagged with their MITRE ATT&CK technique ID so you can see exactly where on the attacker kill-chain an event lives, and what typically comes next.
A report a human can read.
Every scan produces a forensic investigation report, generated by AI, in plain English. No jargon. No 400-page PDF. Just answers.
See a sample reportAlways watching. Never in the way.
The Alfacotex monitor daemon runs silently in the background, watching for suspicious events. When something happens, you know immediately, and you can act in one tap.
- Real-time OS-native detectionSysmon on Windows, auditd on Linux, Unified Log on macOS.
- Push + email alertsInstant notifications the moment a suspicious event is flagged.
- One-tap scan from any alertSee an alert and immediately launch a targeted scan from the notification.
Your whole device fleet, in one dashboard.
Find out what's really on your machine.
Run a forensic-grade scan in minutes. No security background required. Pay only for what you scan.