Features

What each part of Aftermath actually does.

Seven capabilities, each solving one specific part of a post-infection cleanup — not a feature list, a set of reasons.


01
01 — Investigation

See what removal left behind.

Problem

Detection and removal don't always clear everything a file dropped along the way.

Aftermath

Checks Artifacts, Startup, Persistence, Network, and System in one pass.

Result

A complete picture, instead of a guess at what else to check.

Aftermath — Artifacts
Artifacts found
Dropped file: svhost32.tmp%TEMP% · created during infection windowFlagged
Modified shortcut: Chrome.lnkTarget path alteredFlagged

02
02 — Persistence

Find what's set up to survive a reboot.

Problem

Run keys and scheduled tasks are how a threat comes back after a restart.

Aftermath

Checks run keys, scheduled tasks, and the startup folder against what's expected.

Result

Entries that don't belong get flagged before the next reboot.

Aftermath — Persistence
Startup & persistence entries
RunOnce: updater32.exeNot in original install manifestFlagged
Scheduled task: SystemCheckSvcCreated after infection windowFlagged

03
03 — Drift

Know the moment something changes.

Problem

Without a record of "normal," a silent reinfection looks like nothing at all.

Aftermath

Saves a baseline of the clean machine, then compares against it on demand.

Result

A flagged difference instead of a mystery three weeks later.

Aftermath — Drift
Since last baseline — 3 changes
New scheduled taskSystemCheckSvc, created 04:12 AMNew
Modified run keyHKCU\...\Run — value changedChanged

04
04 — Quarantine

Remove it without betting on delete.

Problem

Permanent deletion is unforgiving when a call turns out to be wrong.

Aftermath

Moves flagged items to a quarantine that can be restored, not deleted, by default.

Result

A wrong call doesn't turn into a second incident.

Aftermath — Cleanup
Quarantine — restorable
updater32.exeQuarantined 10:41 AMRestore available
SystemCheckSvc.taskQuarantined 10:42 AMRestore available

05
05 — Sweep

Cover more than one machine.

Problem

One infected machine rarely tells you if others on the same network are exposed too.

Aftermath

Pushes the same triage to a host list, agentless, no software pre-deployed.

Result

The same visibility across several machines from one session. Details →

Aftermath — Sweep
Host list — 5 machines
FRONTDESK-PCTriage completeClean
BACKOFFICE-011 flagged entryFlagged

06
06 — Reporting

Leave a record, not a memory.

Problem

Cleanup happened, but there's nothing to show for it once the ticket closes.

Aftermath

Exports a branded PDF summarizing findings, actions taken, and when — Pro and Max tiers.

Result

A document that closes the ticket. Details →

Aftermath — Session Report

Generated 5:02 PM
Summary
Threats found2
Items quarantined3

07
07 — Settings & control

Nothing about how it runs is hidden.

Problem

Tools that quietly decide what to check or how long to keep data are hard to trust.

Aftermath

Scan behavior, data retention, and administrator controls are all plain settings.

Result

You decide how it behaves — nothing configured behind the scenes.

Aftermath — Settings
Configuration
Data retentionHistory kept 90 daysSet
LicenseSettings → LicenseActive

Every feature above is in the free tier's core, or one upgrade away.