Deep Scan
Focused, deeper scanning of the specific points, systems, and artifacts that require more than Quick Scan can give. Where Quick Scan triages, Deep Scan investigates: the files, scripts, and artifacts behind a suspicious finding.
When Quick Scan flags suspicion, Deep & Forensic Intelligence takes over. Deeper scanning, forensic timeline correlation, and persistence investigation across snapshot history, so the recovery decision accounts for what happened before the visible point of compromise.
Quick Scan is built for fast triage across the environment. It tells you where to look next, but it is not built to answer harder questions: how far back does this go, did the attacker sit quietly before the visible event, and which artifacts actually prove it.
Deep & Forensic Intelligence investigates the candidates Quick Scan flags, builds a timeline of findings across snapshots, and looks for the slow, gradual, or dormant activity that a single-point scan would miss, before the recovery decision is made.
Deep & Forensic Intelligence enters when Quick Scan indicates suspicion. It builds the evidence Quick Scan cannot, then feeds it back into the same recovery decision.
Focused, deeper scanning of the specific points, systems, and artifacts that require more than Quick Scan can give. Where Quick Scan triages, Deep Scan investigates: the files, scripts, and artifacts behind a suspicious finding.
Compares findings and changes across snapshots along the timeline to bound the incident and trace how the compromise progressed, workload by workload, snapshot by snapshot.
Investigates historical patterns and Slow-Moving Attack behavior to identify activity that began before the visible point of compromise, gradual, dormant, or staged intrusions that a single scan would not surface.
Deep & Forensic Intelligence does not produce a separate output. Its findings feed directly into the recovery verdict: safe to resume, requires investigation, or unsafe to resume.
Deep Scan and timeline correlation found no earlier compromise. The candidate holds.
Gradual or dormant activity detected earlier in the timeline. Recommends a wider investigation window.
Forensic evidence shows compromise began before the visible event. This candidate is out.
Book a demo and we will walk through Deep Scan, timeline correlation, and forensic investigation against a real recovery scenario.