OPEN SOURCE • WINDOWS SECURITY

Find the Windows processes
that flash and disappear.

Inspector monitors short-lived Windows processes with Sysmon, correlates them with startup and persistence locations, and turns the evidence into an interactive investigation report.

MIT License Windows 10/11 .NET 8 Open source
Inspector/Security Investigation
Live capture A
TUESDAY, OCTOBER 08, 2024

Security Investigation

12Captured
2Investigate
3Unknown
7Benign
Activity timelineLast 24 hours
00:0006:0012:0018:00Now
Captured events12 events
TIMEPROCESSPARENTCOMMANDRISK
08:42:11powershell.exeexplorer.exepowershell -ExecutionPolicy...Investigate
08:42:12cmd.exepowershell.execmd /c schtasks /run...Unknown
08:42:14wscript.exeexplorer.exewscript C:\\Users\\Public...Investigate
SELECTED EVENT ×

powershell.exe

Investigate08:42:11.408
Parent process
explorer.exe
Executable
C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe
Command line
powershell -ExecutionPolicy Bypass -File update.ps1
Signature
Microsoft Windows
Startup location
Registry Run key · HKCU\\...\\Run
Realistic product previewLocal-first monitoring
THE PROBLEM

Ever seen this?

Some processes exist for less than a second. That's long enough for Windows to record them — but often too short for you to see what happened.

Inspector keeps the evidence.

01
DesktopDocumentsBrowser
Normal desktop
02
powershell.exe
A window flashes
03
Inspector captures it
CAPABILITIES

See what Windows
doesn't show you.

Everything you need to turn a fleeting process into a clear, defensible trail of evidence.

Short-lived process capture

Catch processes that appear and disappear before you can inspect them manually.

Startup & persistence correlation

Connect process activity with Registry Run keys, Scheduled Tasks and other autostart locations.

Interactive reports

Turn raw event data into a readable investigation timeline.

Parent process chains

Understand what launched what, from the first parent to the final command.

Signed / unsigned detection

Quickly distinguish signed executables from unsigned ones.

Search & filter

Find the process, command line or event you are looking for.

Baseline comparison

Save an autostart baseline and compare changes later.

AI-assisted analysis

Generate a structured analysis prompt for your preferred AI assistant.

HOW IT WORKS

From event to evidence.

One focused pipeline. No dashboard to configure, no cloud account to create.

01

Sysmon

Windows records process creation events.

02

Inspector service

Inspector watches relevant Sysmon events in real time.

03

Correlation

Process activity is connected with persistence locations.

04

Investigation

Generate an interactive report and investigate what happened.

UNDER THE HOOD

A local pipeline built
for clarity.

Inspector stays close to the source, so every step from event to report is easy to understand.

WINDOWSOperating system
SYSMONProcess event log
INSPECTOR SERVICEReal-time watcher
LOCAL CAPTUREJSONL evidence
INSPECTOR REPORTCorrelation engine
INTERACTIVE HTML REPORTInvestigate locally
REPORT SHOWCASE

From raw events
to an investigation.

Readable by humans. Detailed enough to follow the chain. Built for the moment you need answers.

SummaryToday
12captured2investigate7benign
01

Summary dashboard

See the shape of the day before drilling into an event.

explorer.exe
powershell.exe
wscript.exe
02

Parent process chain

Understand what launched what.

Startup inventory
Registry Run14 items
Scheduled Tasks28 items
WMI subscriptions3 items
03

Autostart inventory

Persistence locations, in one view.

LOCAL-FIRST BY DESIGN

Your system data
stays yours.

Inspector is designed around local Windows monitoring. Captured process data is stored locally for investigation. No cloud dashboard is required.

Read the source
LOCAL-FIRSTData stays on your machine by default
NO ACCOUNT REQUIREDInstall and investigate locally
OPEN SOURCEMIT licensed and built in the open
OPTIONAL WORKFLOW

Bring your
own AI.

Inspector can generate a structured analysis prompt so you can use the AI assistant you already trust. You decide what leaves your machine.

See the workflow
Inspector report
Copy analysis prompt
ChatGPT / Claude / other AI
Security explanation
GET STARTED

Three commands.
Then investigate.

Inspector gives you a focused path from install to your first report. Nothing to deploy, nothing to provision.

Read the documentation
PowerShellInspector
PS>.\Inspector.ps1 -Install
PS>.\Inspector.ps1 -Activate
PS>.\Inspector.ps1 -Report
FAQ

Good questions are
part of the investigation.

BUILT IN THE OPEN

Open source.
Built to be inspected.

Read the code, run it locally, report issues, and contribute. Inspector is MIT licensed and designed to stay understandable.

MITOpen sourceWindows.NET 8