Platform

Everything Aftermath actually contains.

One desktop app, twelve pages, no detection engine of its own. This is the real page structure — not a mockup of what it might become.


01
01
The interface

Seven of the twelve pages, in the app's own words.

Aftermath — Overview
Threats found2
Quarantined2
Startup entries14
Last scan3m ago
Recent detections
Trojan:Win32/Phonzy.A!mlStartup · QuarantinedRemoved
Trojan:Win32/MalgentScheduled task · QuarantinedRemoved
Detections — everything Defender caught
Trojan:Win32/Phonzy.A!mlDetected 03:47 AM · Real-time protectionRemoved
Trojan:Win32/MalgentDetected 03:52 AM · Scheduled scanRemoved
PUA:Win32/InstallCoreDetected 6 days ago · Real-time protectionResolved
Startup & persistence entries
RunOnce: updater32.exeRegistry · not in original install manifestFlagged
Scheduled task: SystemCheckSvcTask Scheduler · created after infection windowFlagged
OneDrive.exeStartup folder · signed, known-goodNormal
Network artifacts
Outbound connection — 185.220.x.xBlocked by Defender Firewall · loggedFlagged
Proxy setting changedSystem-wide, set outside normal configFlagged
Hosts fileNo unauthorized entries foundClean
Since last baseline — 3 changes
New scheduled taskSystemCheckSvc, created 04:12 AMNew
Modified run keyHKCU\...\Run — value changedChanged
New browser extensionChrome — "PDF Helper" installedNew
Quarantine — restorable
updater32.exeQuarantined 10:41 AMRestore available
SystemCheckSvc.taskQuarantined 10:42 AMRestore available
PDF Helper (extension)Quarantined 10:43 AMRestore available
Host list — 5 machines
FRONTDESK-PCTriage complete · no findingsClean
BACKOFFICE-01Triage complete · 1 flagged entryFlagged
WAREHOUSE-03Triage in progressRunning
Overview — real page names, illustrative data

02
02
Architecture

Deliberately not a second antivirus engine.

Aftermath doesn't rescan your files or claim to catch what Defender missed. It reads the verdicts Defender already reached, then investigates what's left behind — startup entries, scheduled tasks, network artifacts — that a detect-and-delete cycle doesn't always clear on its own.


03
03
Investigation surfaces

Every place an infection tends to hide, in one app.

What's running

  • Detections
  • Exposure
  • History

What persists

  • Startup
  • Persistence
  • Artifacts

What changed

  • Network
  • System
  • Drift

04
04
Cleanup, records, and control

Quarantine, not delete

Every removal is restorable by default until you purge it yourself.

Drift baselines

Save a clean snapshot; get flagged the moment something changes.

Sweep

Push the same triage to a host list — agentless, no standing account. Learn more →

Branded reports

Exportable PDF record of a session — Pro and Max tiers. Learn more →


See it running on your own machine.