How it works

Five steps. No new engine to trust.

This is the actual investigation, in order — what Aftermath looks at, what shows up on screen, and what a technician can decide at each stage.


01
01
Read

Pull the verdicts you already have.

  • What happensAftermath reads Windows Defender's own detection history and event logs on launch.
  • What it's looking atDefender's threat log, Windows Event Viewer entries, and scan history — nothing Aftermath scans itself.
  • What the technician seesOverview: how many threats were found, how many are quarantined, when the last scan ran.
  • OutputA starting picture of what's already been caught, before any manual digging begins.
Aftermath — Overview
Threats found2
Quarantined0
Startup entries14
Last scan3m ago
Read from Defender
Trojan:Win32/Phonzy.A!mlDetected 03:47 AMPresent
Trojan:Win32/MalgentDetected 03:52 AMPresent

02
02
Investigate

Find what removal left behind.

  • What happensAftermath walks Startup, Persistence, Network, and System looking for anything Defender's cleanup didn't touch.
  • What it's looking atRun keys, scheduled tasks, browser extensions, startup folder contents, and recent network changes.
  • What the technician seesA flagged list — entries that don't match a known-good baseline or install manifest.
  • DecisionsConfirm each flagged item is actually unwanted before it moves to quarantine.
Aftermath — Persistence
Startup & persistence entries
RunOnce: updater32.exeNot in original install manifestFlagged
Scheduled task: SystemCheckSvcCreated after infection windowFlagged
OneDrive.exeSigned, known-goodNormal

03
03
Quarantine

Remove it, without guessing.

  • What happensConfirmed items move out — the registry key, the scheduled task, the extension — in one action.
  • What it's looking atEach item's exact location, so removal is reversible instead of a blind delete.
  • What the technician seesA quarantine list with a restore option next to every entry.
  • OutputThe machine is clean, and every action taken is logged with a timestamp.
Aftermath — Cleanup
Quarantine — restorable
updater32.exeQuarantined 10:41 AMRestore available
SystemCheckSvc.taskQuarantined 10:42 AMRestore available

04
04
Baseline

Snapshot the clean state.

  • What happensOnce the machine is clean, Aftermath saves a Drift baseline — the current state of startup, persistence, and system settings.
  • What it's looking atEvery entry the earlier steps just reviewed, recorded as "known good."
  • What the technician seesA future scan compares against this baseline and flags anything new as a difference, not a mystery.
  • OutputA silent reinfection shows up as a flagged change instead of a repeat ticket weeks later.
Aftermath — Drift
Baseline saved — 0 changes since
Startup entries14 recorded as known-goodBaseline set
Scheduled tasks6 recorded as known-goodBaseline set

05
05
Sweep

Repeat it across other machines.

  • What happensIf one machine wasn't the only one at risk — same network, same install source — Sweep pushes the same triage to a host list.
  • What it's looking atWhatever host names or addresses you provide — Aftermath doesn't discover machines on its own.
  • What the technician seesA per-host status: clean, flagged, or still running.
  • OutputThe same visibility across several machines, agentless, no standing account.
Aftermath — Sweep
Host list — 5 machines
FRONTDESK-PCTriage completeClean
BACKOFFICE-011 flagged entryFlagged

Run this on the machine in front of you.