PRICING // THREE TIERS // SUBSCRIPTION
Pick your hunt.
The full read-only audit — see every hook that survives reboot, no deletion.
- Full persistence audit — Run keys, Startup, tasks, services, WMI, CLSID, cron/systemd, autostart
- Exact findings — paths, registry keys and PIDs
- Manual file/folder scan over YARA signatures
- Behavioural monitoring — eBPF / ETW
- Removal & auto-cleanup — read-only
Everything in the Free audit, plus one-click removal of every confirmed persistence hook.
- All Free features — Run keys, tasks, services, WMI, CLSID, cron/systemd, autostart
- Exact findings — paths, registry keys and PIDs
- One-Click Auto-Purge — removes confirmed hooks safely
- Rollback of hijacked services and COM registrations
- Quarantine of files and processes
- Real-Time Autorun Shield — detects new autorun hooks
- CLI / portable USB / forensic export
Everything in Standard, plus full control of the Real-Time Shield — and priority support for the term.
- All Standard features
- Real-Time Shield controls — process allowlist (exclusions) and notification settings
- Priority support & updates during the term
- CLI / portable USB / forensic export
Everything in Pro, built for IR teams and analysts — scriptable and portable.
- All Pro features
- CLI mode — scriptable, JSON output, exit codes
- Portable version — run from a USB stick, no install
- Forensic JSON/HTML export — persistence → process → PID chain with timestamps
| Capability | Standard $9 | Pro $29 | Business $99 |
|---|---|---|---|
| Full local C++ scan (WMI · tasks · Run keys · services · COM · memory) | ✓ | ✓ | ✓ |
| Exact paths, registry keys and PIDs | ✓ | ✓ | ✓ |
| Process hollowing / injection detection | ✓ | ✓ | ✓ |
| One-Click Auto-Purge | ✓ | ✓ | ✓ |
| Rollback of hijacked services & COM | ✓ | ✓ | ✓ |
| Quarantine of files and processes | ✓ | ✓ | ✓ |
| Real-Time Autorun Shield (detection) | ✓ | ✓ | ✓ |
| Shield controls — exclusions & notifications | — | ✓ | ✓ |
| CLI mode (JSON output) | — | — | ✓ |
| Portable version (run from USB) | — | — | ✓ |
| Forensic JSON/HTML export | — | — | ✓ |
| Zero cloud · zero telemetry · offline | ✓ | ✓ | ✓ |
| Term (subscription) | 30 days | 90 days | 365 days |
| Free updates during the term | ✓ | ✓ | ✓ |
Subscription, not lifetime
Terms are 30, 90 or 365 days per tier. Renew before the term ends to extend from the current expiry date — no interruption, no re-activation.
How you get your key
After the crypto payment clears, your licence key is ready. Claim it on the paid page (paid.html) by entering the email you used at checkout. Paid without an email? Write to [email protected] and we deliver it manually.
Activation
The key is entered in the desktop app, which activates it against our license server. No cloud scanning — only a short activation handshake, then everything runs fully offline.
Roadmap. Scheduled periodic audits are in development and not part of any current tier. Downloads, exports and one-off scans are available today.
Unsure which tier? Start with the Free audit. It shows you everything your machine is hiding — then upgrade only if you want the hooks removed, live shielding or the forensic export. Download the free version.
Found hooks? Purge them.
Free audit, Standard $9/30d, Pro $29/90d, Business $99/365d — subscription, zero cloud. Claim your licence key on the confirmation page after payment.