AFTERMATH


Aftermath shows you exactly what an infection changed on a Windows machine, and helps you undo it — after your antivirus has already caught the threat.

Defender flags the file. It doesn't tell you about the startup entry, the scheduled task, or the browser extension it left behind. Aftermath finds that — so the same machine doesn't come back to you in three weeks.

Version
1.5.0
Platform
Windows x64
Size
0.8 MB
License
Free tier available
Aftermath — Overview
Threats found2
Quarantined2
Startup entries14
Last scan3m ago
Recent detections
Trojan:Win32/Phonzy.A!ml Startup · Quarantined Removed
Trojan:Win32/Malgent Scheduled task · Quarantined Removed
A representative Aftermath session — real page names, illustrative data

01
01
The problem

"Threat removed" is where most tools stop. It's rarely where the problem actually ends.

Without Aftermath
  • Defender closes the alert, no record of what else was checked
  • Startup entries and scheduled tasks checked by hand, tool by tool
  • No way to tell if a later problem is a new infection or the same one
  • Every machine gets the same manual walkthrough, from scratch
With Aftermath
  • One place to see everything Defender already caught
  • Startup, persistence, and network artifacts checked in one pass
  • A saved baseline flags anything that changes afterward
  • The same triage runs against every machine that needs it

02
02
The platform

A real desktop app, not a concept.

Aftermath runs locally on Windows 10/11 — no account, no cloud upload, no second detection engine pretending to compete with Defender. What's below is the actual page structure.

Windows 10/11 No account required No cloud upload

Aftermath finds what changed since the last clean scan — it does not itself decide whether Defender's original detection was correct. That judgment call is still yours; Aftermath's job stops at showing you everything the infection left behind.

Aftermath — Overview
Threats found2
Quarantined2
Startup entries14
Last scan3m ago
Recent detections
Trojan:Win32/Phonzy.A!mlStartup · QuarantinedRemoved
Trojan:Win32/MalgentScheduled task · QuarantinedRemoved
System baselineDrift — no changes since last scanClean
Startup & persistence entries
RunOnce: updater32.exeRegistry · not in original install manifestFlagged
Scheduled task: SystemCheckSvcTask Scheduler · created after infection windowFlagged
OneDrive.exeStartup folder · signed, known-goodNormal
Chrome extension: "PDF Helper"Browser · installed same day as infectionFlagged
Since last baseline — 3 changes
New scheduled taskSystemCheckSvc, created 04:12 AMNew
Modified run keyHKCU\...\Run — value changedChanged
New browser extensionChrome — "PDF Helper" installedNew
Host list — 5 machines
FRONTDESK-PCTriage complete · no findingsClean
BACKOFFICE-01Triage complete · 1 flagged entryFlagged
WAREHOUSE-03Triage in progressRunning
Overview — real page names, illustrative data

03
03
How it works

Five steps. No new engine to trust.

01 — Read

Pull the verdicts you already have

Aftermath reads Windows Defender's own detection history and event logs. It never rescans your files or claims to catch something Defender missed.

02 — Investigate

Find what removal left behind

Startup entries, scheduled tasks, persistence keys, network artifacts — checked in one pass instead of five separate native tools.

03 — Quarantine

Remove it, without guessing

Flagged items move to a restorable quarantine — not a permanent delete — so a wrong call doesn't break the machine.

04 — Baseline

Snapshot the clean state

Drift compares the machine against that snapshot later, so a silent reinfection shows up as a flagged change, not a mystery.

05 — Sweep

Repeat it across other machines

When one machine isn't the only one at risk, Sweep pushes the same triage to a host list — agentless, no standing account.


04
04
Built for real work

Situations Aftermath was actually built to handle.

Problem

A machine gets cleaned, but something comes back a few weeks later. Nobody knows if it's a new infection or the same one that never fully left.

Aftermath

A saved baseline flags exactly what changed since the last clean scan — the new scheduled task, the modified run key.

Result

The real reinfection vector, instead of a second guessing game.

Problem

Defender says "threat removed" and closes the notification. There's no visibility into whether anything else is still on the machine.

Aftermath

Detections, Exposure, and History lay out everything Defender caught and what's still present, in one view.

Result

Confidence the cleanup is actually done — not just quiet.

Problem

One person is responsible for several machines and there's no budget for a full EDR platform to watch all of them.

Aftermath

Sweep pushes the same triage to a host list — agentless, no software to deploy ahead of time, no standing account.

Result

The same visibility across several machines, without a new platform to buy.

Problem

Cleanup was done, but there's nothing to show for it afterward — no record of what was found or removed.

Aftermath

Pro and Max tiers export a branded PDF report straight from a session.

Result

A record that closes the ticket, instead of a memory of what happened.


05
05
Business value

What actually changes when you use it.

Save time

One pass through Startup, Persistence, and Network instead of five separate native tools, checked by hand.

Catch what's easy to miss

A saved baseline flags silent changes automatically — no need to remember what "normal" looked like.

Move faster on real tickets

Detections and History put what Defender already found in front of you immediately, not buried in Event Viewer.

Cover more ground

Sweep repeats the same triage across a host list without deploying agents ahead of time.

Undo safely

Quarantine, not permanent delete, by default — a wrong call doesn't turn into a second incident.

Leave a record

A branded, exportable report closes the loop on what was found and what was done about it.


06
06
Scale

Starts on one machine. Doesn't stop there.

Free — Max

One machine

No account, runs fully offline. Free covers a real cleanup; Plus/Pro/Max add deeper investigation, Drift baselines, and reporting.

Max — Sweep

A handful of hosts

One person triaging several machines from a single session — agentless push/pull, no software pre-deployed, no standing account.

Enterprise

The organization

Fleet, a separate product built for this: unlimited hosts, an org account, role-based access, and priority support.


07
07
A day with Aftermath

One technician, one ticket, start to finish.

  • 8:03 AM

    A ticket comes in

    Defender flagged something on a shared machine overnight. The alert says "threat removed" — nothing else.

  • 9:17 AM

    Overview shows the full picture

    Two detections already quarantined by Defender. Persistence shows three startup entries Defender never touched.

  • 10:42 AM

    Cleanup runs

    The leftover entries move to quarantine. History logs the action with a timestamp, restorable if anything breaks.

  • 1:15 PM

    A baseline gets saved

    Drift now has a clean snapshot of this machine — any future change shows up as a flagged difference, not a surprise.

  • 3:40 PM

    Sweep checks the neighbors

    Four other machines shared the same network drive. Sweep runs the same triage against all four from one session.

  • 5:02 PM

    The ticket closes with a record

    A branded PDF export goes into the ticket — what was found, what was removed, and when.


08
08
Centralization

Aftermath doesn't replace Defender. It replaces the pile of native tools you'd otherwise open around it.

  • Autoruns — startup entries
  • Event Viewer — detection history
  • Task Scheduler — scheduled tasks
  • Registry Editor — persistence keys
  • Browser extension lists — hijacked settings
  • A text file of notes — what you found, where
One Aftermath session Detections, Exposure, History, Artifacts, Startup, Persistence, Network, System

09
09
Trust & control

No detection engine of its own, so there's nothing about its findings to take on faith — only how it handles them.

Activity history

Every scan, quarantine action, and Drift check is logged locally.

Data retention

Control how long History and Artifacts are kept, from Settings.

Scan behavior

Configure what Aftermath watches, in plain settings — nothing hidden.

Administrator controls

Transparent about exactly which actions need elevated rights, and why.

Quarantine, not delete

Every removal is restorable by default until you purge it yourself.

License management

See and manage your tier directly from Settings → License.

Branded reports

Exportable PDF record of a session — Pro and Max tiers.

Permissions & privacy

Clear about exactly what Aftermath reads and touches, and nothing more.


10
10
Why Aftermath
Manual approachAftermath
Hunt across Autoruns, Event Viewer, Task Scheduler, and the registry separatelyOne view: Detections, Startup, Persistence, Network, System
Run a second AV engine and hope it agrees with the firstReads the verdicts your existing Defender already reached — no second engine to trust
Delete and hope nothing breaksQuarantine with restore, not permanent by default
Repeat the same walkthrough by hand on every machineSweep pushes the same triage to a host list, agentless
No record of what was actually doneBranded, exportable report — Pro and Max tiers

11
11
Pricing

Free covers a real cleanup. Paid tiers cover the next one — and the one after that, across more machines.

Free

$0

Scan, quarantine & restore, Detections, Exposure, History.

Get started
Most popular Pro

$1.33/mo

$9/yr $16/yr

44% off

Scheduled Drift baselines, branded PDF report, unlimited history.

View plan
Max

$2.79/mo

$19/yr

Attack-chain timeline, custom scan profiles, Sweep up to 5 hosts.

View plan

See every tier, including Enterprise Fleet →


See what Aftermath can do for your machines.

Explore how it fits into your team's cleanup workflow, from one PC to several.

Pricing  ·  Log in  ·  Enterprise  ·  Aftermath, by SINVAUX