Short-lived process capture
Catch processes that appear and disappear before you can inspect them manually.
Inspector monitors short-lived Windows processes with Sysmon, correlates them with startup and persistence locations, and turns the evidence into an interactive investigation report.
Some processes exist for less than a second. That's long enough for Windows to record them — but often too short for you to see what happened.
Inspector keeps the evidence.
Everything you need to turn a fleeting process into a clear, defensible trail of evidence.
Catch processes that appear and disappear before you can inspect them manually.
Connect process activity with Registry Run keys, Scheduled Tasks and other autostart locations.
Turn raw event data into a readable investigation timeline.
Understand what launched what, from the first parent to the final command.
Quickly distinguish signed executables from unsigned ones.
Find the process, command line or event you are looking for.
Save an autostart baseline and compare changes later.
Generate a structured analysis prompt for your preferred AI assistant.
One focused pipeline. No dashboard to configure, no cloud account to create.
Windows records process creation events.
Inspector watches relevant Sysmon events in real time.
Process activity is connected with persistence locations.
Generate an interactive report and investigate what happened.
Inspector stays close to the source, so every step from event to report is easy to understand.
Readable by humans. Detailed enough to follow the chain. Built for the moment you need answers.
See the shape of the day before drilling into an event.
Understand what launched what.
Persistence locations, in one view.
Inspector is designed around local Windows monitoring. Captured process data is stored locally for investigation. No cloud dashboard is required.
Read the sourceInspector can generate a structured analysis prompt so you can use the AI assistant you already trust. You decide what leaves your machine.
See the workflowInspector gives you a focused path from install to your first report. Nothing to deploy, nothing to provision.
Read the documentation.\Inspector.ps1 -Install.\Inspector.ps1 -Activate.\Inspector.ps1 -ReportRead the code, run it locally, report issues, and contribute. Inspector is MIT licensed and designed to stay understandable.