Threat Detection

LogGuard

The first thing malware does after gaining access is destroy the evidence. LogGuard makes that impossible — kernel-level protection for your Windows event logs, with real-time threat detection and cryptographic integrity proof.

Protection, detection, and proof

LogGuard isn't a SIEM — it prevents log destruction and detects threats in real time, right on the endpoint.

Kernel-Level Log Protection

A minifilter driver blocks deletion, renaming, and truncation of .evtx event log files. Malware can't wipe the evidence even with SYSTEM privileges.

SHA-256 Hash Chain

Every log event is added to an HMAC hash chain. If a single event is modified, inserted, or removed, the chain breaks — providing cryptographic proof of tampering or integrity.

LogVault

A driver-protected tamper-proof mirror of your event logs. Even if an attacker bypasses the event log service, the vault copy remains intact and verifiable.

Was I Hacked?

One-click scan that checks hundreds of indicators and returns a simple GREEN / YELLOW / RED verdict. No security expertise required — just click and get your answer.

Ransomware Early Warning

Detects mass file rename and delete operations that signal ransomware encryption in progress. Alerts fire at the first sign of anomalous bulk file operations.

USB Device Tracking

Monitors USB device connections with known/unknown device classification. Know exactly what devices have been plugged into your machine and when.

MITRE ATT&CK Mapping

Every detection is mapped to MITRE ATT&CK techniques. Understand exactly what an attacker is doing in standardized, industry-recognized terminology.

Compliance Reporting

Generate reports mapped to PCI DSS, HIPAA, and SOX requirements. Prove your log integrity and security posture for audits and compliance reviews.

Baseline Anomaly Engine

Learns your system's normal behavior over 7 days, then alerts on statistical deviations. Catches unusual activity even if it doesn't match a known attack signature.

PowerShell Script Capture

Captures and risk-scores every PowerShell script execution (EventID 4104). See exactly what scripts ran, when, and how suspicious they are.

Dual UI Mode

Simple home mode with the "Was I Hacked?" button and clean dashboard. Toggle to IT Pro mode for SIGMA rules, forensic export, remote forwarding, and chain verification.

No Feature Gating

Every license tier gets every feature. Personal users get the same protection as enterprise. The only difference is fleet management and machine count.

Hosted Remote Log Backup

Forward your logs to our secure servers for off-site backup. 30-day retention with a web portal for search and export.

Encrypted Off-Site Storage

Logs are forwarded over TLS and stored encrypted. Even if your machine is compromised, your log history is safe on our servers.

Web Portal

Search, filter, and export your remote logs from any browser. Full-text search across 30 days of history.

$2.99/month per machine

Volume discounts available at 10+ machines. Cancel anytime.

All features. Every tier.

LogGuard doesn't gate features by price. Every user gets full protection.

Business
$49.99
per year · fleet management
Multi-machine management, central administration, priority support.
Hosted Backup Add-on
$2.99
per month · per machine
30-day remote log retention. Web portal. Volume discounts at 10+.

Know if you've been hacked

One click. Green, yellow, or red. It's that simple.

Get LogGuard