Each pillar is a standalone capability. Together they form the execution genome — a multi-dimensional behavioral fingerprint of every Windows process.
PILLAR 01
PE//SCAN
Zero-dependency PE parser. Import categorization, entropy analysis, security assessment, ROP gadget scanning. Every byte parsed by hand in Rust.
PHASE 0 · LIVE
PILLAR 02
CALL//CHAIN
ETW-based temporal execution graphs. Causal edges, temporal correlation, and 8 built-in behavioral signatures mapped to MITRE ATT&CK.
PHASE 1 · LIVE
PILLAR 03
EXPOSURE//MAP
Quantified attack surface across five dimensions. Runtime CVSS for process instances — not for software vulnerabilities, but for instantaneous exploitability.
STATIC · LIVE
PILLAR 04
SHIELD//MAP
Defensive counterpart to EXPOSURE//MAP. Maps imports to 14 attack chains, identifies missing controls, and generates prioritized remediation with PowerShell commands.
PHASE 1 · LIVE
PILLAR 05
DEBUG//BRIDGE
WinDbg integration via DbgEng API. Memory inspection, PEB/TEB walking, gadget resolution with ASLR-adjusted virtual addresses and bad-char filtering.
PHASE 1 · LIVE
PILLAR 06
LIB//GRAPH + RESOURCE//PULSE
DLL usage profiling fused with CPU/memory/IO telemetry. Burst detection, crypto fingerprinting, hardware performance counter correlation. 7 fused alert rules.
PHASE 2 · LIVE
PILLAR 07
GENOME//DIFF
6-dimension behavioral genome: PE structure, API graph, exposure, shield, DLL usage, and resource telemetry. Multi-dimensional diffing catches supply chain and injection mutations.
PHASE 3 · LIVE
PILLAR 08
ARTIFACT//SWEEP
Forensic collection across 5 categories with TRACE//LAB behavioral correlation. Prefetch, shimcache, registry persistence, VAD entries, network state — evidence with context.
PHASE 3 · LIVE
PILLAR 09
TRACE//QL
Pipeline query language for all TRACE//LAB dimensions. Lexer, recursive descent parser, typed AST, execution engine with 12 pipeline stages. Interactive REPL and single-shot mode.
QUERY · LIVE
PILLAR 10
DETECTION EXPORT
20 detection rules exported to Sigma YAML, Splunk SPL, and Elastic EQL. Bridges behavioral analysis directly into SOC tooling for production deployment.
SOC · LIVE
PILLAR 11
THREAT//INTEL
IoC extraction from PE analysis, trace events, and forensic artifacts. Threat scoring, CTI source enrichment model, STIX 2.1 bundle export for threat sharing.
CTI · LIVE
PILLAR 12
COMPLIANCE
Maps SHIELD//MAP controls to NIST CSF 2.0, CIS Controls v8.1, ISO 27001:2022, CMMC 2.0, and NIST 800-53 Rev 5. Per-framework gap analysis with remediation priorities.
GRC · LIVE