Use cases

Situations Aftermath was actually built to handle.

Four real scenarios, not a hypothetical feature tour. Each one is the reason a specific part of Aftermath exists.


01
Scenario 01

The reinfection loop

Problem

A machine gets cleaned, but something comes back a few weeks later. Nobody knows if it's a new infection or the same one that never fully left.

Aftermath

A saved Drift baseline flags exactly what changed since the last clean scan — the new scheduled task, the modified run key — instead of a fresh full investigation.

Result

The real reinfection vector, instead of a second guessing game.

Aftermath — Drift
Since last baseline — 3 changes
New scheduled taskSystemCheckSvc, created 04:12 AMNew
Modified run keyHKCU\...\Run — value changedChanged
New browser extensionChrome — "PDF Helper" installedNew

02
Scenario 02

The uncertain cleanup

Problem

Defender says "threat removed" and closes the notification. There's no visibility into whether anything else is still on the machine.

Aftermath

Detections, Exposure, and History lay out everything Defender caught and what's still present, in one view.

Result

Confidence the cleanup is actually done — not just quiet.

Aftermath — Overview
Threats found2
Quarantined2
Recent detections
Trojan:Win32/Phonzy.A!mlStartup · QuarantinedRemoved

03
Scenario 03

Several machines, one person

Problem

One person is responsible for several machines and there's no budget for a full EDR platform to watch all of them.

Aftermath

Sweep pushes the same triage to a host list — agentless, no software to deploy ahead of time, no standing account.

Result

The same visibility across several machines, without a new platform to buy. See Sweep →

Aftermath — Sweep
Host list — 5 machines
FRONTDESK-PCTriage completeClean
BACKOFFICE-011 flagged entryFlagged
WAREHOUSE-03Triage in progressRunning

04
Scenario 04

Closing the ticket

Problem

Cleanup was done, but there's nothing to show for it afterward — no record of what was found or removed.

Aftermath

Pro and Max tiers export a branded PDF report straight from a session.

Result

A record that closes the ticket, instead of a memory of what happened. See Reporting →

Aftermath — Session Report

Generated 5:02 PM
Findings
Trojan:Win32/Phonzy.A!mlRemoved
Trojan:Win32/MalgentRemoved

See which of these fits your day.