Skip to content
Autonomous DFIR

Forensics. Decode. Truth.

When enterprises get hacked, they call a DFIR firm. You shouldn't need a $50,000 retainer to find out if someone's been on your machine.

2 to 60min
scan time
3OS
platforms
0
contract
000°090°
PID 4821
powershell.exe
DNS
evil-c2.ru
Registry
HKLM\...\Run
Outbound
185.x.x.x:443
Scanning · 4 anomalies detected
WindowsmacOSLinux
No security expertise required
The Problem

You probably won't find out you've been hacked.

Antivirus is built for known malware. Sophisticated attackers don't use known malware. They live in your processes, your scheduled tasks, your registry. Invisible to consumer tooling.

207days

Average attacker dwell time before detection.

40%+

Of advanced threats missed by traditional antivirus.

$50K+

Typical DFIR firm engagement to investigate one incident.

01Scan Depths

Three scan depths. One platform.

Pick the depth you need, pay per scan. From a quick health check to a full forensic investigation.

STD/2 to 5 min

Surface Sweep

Quick health check. Catches obvious threats fast.


  • Running processes & connections
  • Active persistence items
  • DNS cache snapshot
  • Startup entries
See pricing
MED/10 to 20 min

Behavioral Analysis

Broader behavioral signal. Catches stealthier threats.


  • Full process tree
  • Scheduled tasks & cron
  • Registry run keys
  • Browser extension audit
  • 7-day event log review
See pricing
Flagship
DEEP/30 to 60 min

Full Investigation

Forensic-grade. The same depth a DFIR firm would charge $50k for.


  • Complete filesystem timeline
  • MFT & shellbag analysis
  • WMI subscription audit
  • IOC enrichment (VT + AbuseIPDB)
  • MITRE ATT&CK mapping
  • Full attack reconstruction
See pricing
02Workflow

From signup to forensic clarity in under an hour.

01

Create your account

Sign up and verify your email. We never ask for credit cards before your first scan.

30s
02

Install the agent

Lightweight desktop agent for Windows, macOS, and Linux. Sits in your system tray. Enrolls in one click.

2 min
03

Run a scan

Pick Standard, Medium, or Deep. Pay only for what you run. Real-time progress in the dashboard.

2 to 60 min
04

Read your report

Risk score, plain-English findings, attack timeline, MITRE ATT&CK map, and a prioritized action plan.

in your inbox
03Why Alfacotex

Built for forensic clarity, not security theater.

100%

Local-First

Telemetry is collected and analyzed on your own device. Your forensic data never leaves your hardware without consent.

Forensic Depth

MFT, shellbags, WMI subscriptions, registry timelines. The same artifacts a DFIR firm pulls in week-long engagements.

T1003.001 / credential dumping detected (lsass)
An attacker tried to steal your saved passwords from system memory. Rotate credentials and isolate this host.
AI is reasoning…

AI Reports

AI translates raw forensic artifacts into plain English. What it means, why it matters, what to do next.

04 · ATT&CK Mapped

Every finding mapped to a real attacker technique.

Findings are tagged with their MITRE ATT&CK technique ID so you can see exactly where on the attacker kill-chain an event lives, and what typically comes next.

MITRE ATT&CK · Enterprise13 / 14 tactics scanned
TA00011
Initial Access
TA00022
Execution
TA00033
Persistence
TA00041
Privilege Esc.
TA00052
Defense Evasion
TA00063
Credential Access
TA0007
Discovery
TA00111
Command & Control
04AI Reports

A report a human can read.

Every scan produces a forensic investigation report, generated by AI, in plain English. No jargon. No 400-page PDF. Just answers.

See a sample report
scan_2026-06-06_a8f3.report
Deep · 47 min
Risk Score
74/ 100
High Severity · Action Required
What We Found
Critical
Unsigned DLL loaded into lsass.exe
T1003.001credential dumping
Critical
Scheduled task with encoded PowerShell payload
T1053.005persistence via scheduler
Medium
Outbound connection to known C2 IP
T1071abuseipdb confidence: 98%
Timeline
MITRE Map
Action Plan
Alfacotex Monitor
now · MacBook Pro
Suspicious activity detected
An unsigned process attempted to inject into a system binary. Consistent with credential harvesting behavior.
05Continuous Monitor

Always watching. Never in the way.

The Alfacotex monitor daemon runs silently in the background, watching for suspicious events. When something happens, you know immediately, and you can act in one tap.

  • Real-time OS-native detection
    Sysmon on Windows, auditd on Linux, Unified Log on macOS.
  • Push + email alerts
    Instant notifications the moment a suspicious event is flagged.
  • One-tap scan from any alert
    See an alert and immediately launch a targeted scan from the notification.
06Coverage

Your whole device fleet, in one dashboard.

Windows
10 / 11
Scans
Monitor
macOS
Monterey +
Scans
Monitor
Linux
Ubuntu · Debian · Fedora
Scans
Monitor
Mobile
iOS · Android
Coming soon
Built on the standards SOC analysts trust
VELOCIRAPTORMITRE ATT&CKSIGMAVIRUSTOTALABUSEIPDB

Find out what's really on your machine.

Run a forensic-grade scan in minutes. No security background required. Pay only for what you scan.

Free to sign up · Pay per scan · No contract