CFR—Continuous Forensic Reconstruction
RELEASING SOON
Enterprise-Grade Forensic Visibility & Predictive Defense
Distributed, Scalable, and Proactive. The depth of a full forensic investigation at the speed of your network.
Crow-Eye Sentinel delivers the granular, exhaustive details of a complete forensic investigation cycle simultaneously across thousands of endpoints.
But Sentinel doesn't just react to the past—it anticipates the future. By feeding deep endpoint data into our User Behavior Analytics (UBA) engine, Sentinel detects indicators of malicious intent, allowing you to neutralize insider threats before the data ever leaves your network.
Traditional incident response forces you to choose between speed and depth. Sentinel delivers both, bringing the exhaustive artifact parsing power of Crow-Eye to every endpoint in your organization.
Forget shallow triage. Sentinel agents execute complete forensic data collection and artifact parsing locally. Get the exhaustive details of a manual, deep-dive endpoint investigation at enterprise scale, ensuring no registry key, prefetch file, or event log is left unexamined.
Shift from reactive analysis to proactive defense. Sentinel continuously analyzes endpoint artifacts to baseline normal employee behavior. It immediately flags anomalous activities, unauthorized staging, or pre-exfiltration behavior—stopping insider threats before a breach occurs.
Powered by Wing Rules: One size does not fit all in enterprise security. Sentinel’s correlation engine utilizes advanced semantic mapping to automatically stitch together disparate network artifacts into a unified narrative. Powered by Wing Rules, your lead investigators define the logic, hyper-optimizing forensics against unique threat vectors and architectural realities.
Sentinel doesn’t just wait for an investigator to initiate a scan. You can configure deep-dive artifact collections to execute automatically on continuous schedules or instantly trigger based on specific network conditions. This creates a historical forensic safety net. Even if a highly stealthy attack isn't discovered until months later, you will have the exact, granular forensic snapshot captured at the precise moment the initial breach occurred. No more lost evidence due to log rollovers or attacker cleanup.
Sentinel is designed for absolute stability. It runs silently alongside your existing EDR solutions (like CrowdStrike, Microsoft Defender, or SentinelOne) without causing kernel panics, resource conflicts, or operational friction. It provides the deep, granular forensic context that standard EDRs leave behind.
Feed your central nervous system. Seamlessly push parsed forensic timelines, UBA alerts, and Wing Rule detections directly to Splunk, Elastic, Microsoft Sentinel, QRadar, or any webhook-enabled SOAR. Empower your automated playbooks with true forensic intelligence without forcing analysts to leave their single pane of glass.
Visualize the exact delta between two points in time. Sentinel's Comparison View allows investigators to instantly identify new persistence mechanisms, altered artifacts, or deleted evidence between scheduled scans, highlighting the evolving footprint of an adversary across the investigation timeline.
Streamline your investigative workflow with built-in case management. Organize findings, track lead progression, and review critical changes in key forensic artifacts across the entire investigation timeline, ensuring a verifiable and audit-ready record of your work.
CFR is not detection, and it is not a faster DFIR engagement. Detection watches for something that scores as bad and discards the rest. Forensics reads everything — but only once somebody already suspects a breach. CFR reads the same artifacts a forensic examiner would, on a schedule, before anyone asks, so the history already exists when the question finally arrives. Four things have to be true before a product is doing reconstruction rather than collection.
The full artifact set — $MFT, the USN journal, Prefetch, ShimCache, AmCache, ShellBags, SRUM, the registry and the event logs — parsed on a recurring schedule, triggered by the clock rather than by an alert.
Every record threaded by identity and time, across hosts and across months — not scored by a model. The same rules against the same evidence reproduce the same result, every time.
Every claim cites the exact source record — a timestamp, a file, a registry value — on a hash-chained log that can be re-walked. Something you can put in front of a regulator or a court, not a risk score.
Nothing is silently dropped. Every record lands in a result or in a named bucket that explains why it was set aside, so absence is a finding rather than a silence you have to trust.
Three things changed at once, and together they broke the assumption that you can go and collect the evidence later.
81% of attack detections in early 2025 involved no malware at all, and abuse of built-in binaries grew 126% year over year. PowerShell, WMI and PsExec score as legitimate administration by design — there is nothing for a signature to match, and AI is lowering the cost of blending in further.
Windows overwrites its own history: Prefetch and ShimCache cap near 1,024 entries, the USN journal wraps at roughly 32 MB, SRUM is pruned at about 30 days. Median dwell time is 10–14 days — and that median hides the intrusions that ran for months. Collect late and the artifact is simply gone.
GDPR gives 72 hours; the SEC allows 4 business days to determine materiality. Answering "what did this identity touch, and can we prove it didn't touch the data store" is a same-day question now — and the same history is what makes an insider-risk baseline possible at all.
Crow-Eye Sentinel is that engine, running across the whole fleet.
For more details — CFR vs EDR and DFIRBuilt to operate seamlessly in the most demanding, secure, and bandwidth-constrained network environments.
Lightweight agents push the heavy lifting to the edge. By performing local forensic parsing, edge computing ensures your central server is never bogged down by raw data processing.
Your data's security is absolute. Sentinel uses SQLCipher with RAM-locked 256-bit AES keys. Evidence is encrypted in memory before it ever touches the disk on the target endpoint.
Forensic visibility shouldn't break your network. Zstandard (zstd) compression minimizes bandwidth impact, allowing for mass data collection even over strained connections.
Maintain absolute sovereignty over your data. Host your own control server to visualize your entire fleet, correlate UBA alerts, and manage complex investigations from a single dashboard.
Predictable, usage-based licensing metrics. Scale as you grow with a True-Up model that never blocks critical incident response. (Note: Telemetry is strictly for licensing—your forensic data never leaves your hosted environment).
Sentinel is releasing soon — and a small group of design partners is shaping it right now.
We're inviting a limited number of IR firms, MSSPs, internal security teams, and forensic labs to work directly with us before launch. You bring the reality of frontline investigations; we build Sentinel around it. In exchange, you get early enterprise access on the best terms we will ever offer — and a permanent voice in what it becomes.
The open-source Crow-Eye engine is free forever. Sentinel is the paid enterprise platform built on top of it. Design partners get in first, at the best terms we will ever offer.
Design partners can also help build Eye-Describe — the open, byte-level knowledge base of Windows forensic artifacts — and be credited as an educational source. Your expertise becomes part of how the next generation of investigators learns the evidence.
You run real investigations — incident response, insider threat, compliance, or criminal forensics — and you want forensic depth across your whole fleet, not shallow triage. If that's you, we want to build with you.
What security leaders ask before bringing forensic depth to a whole fleet.
Sentinel is the enterprise tier of Crow-Eye. It takes the same full-depth forensic investigation Crow-Eye performs on one machine and runs it across a fleet — distributed agents on thousands of Windows endpoints, reporting into central case management.
An EDR is built to detect and alert in real time. Sentinel is built to reconstruct what actually happened, at fleet scale: it parses and correlates the same deep Windows artifacts a forensic examiner would, so you get an investigable timeline rather than a stream of alerts.
Sentinel is designed for thousands of endpoints. Agents collect and parse locally and forward results, so the work scales with the fleet instead of funnelling every raw artifact to one server.
Yes. Sentinel forwards findings to your existing SIEM, so fleet-wide forensic results land in the pipeline your analysts already watch rather than in another separate console.
Incident response firms, MSSPs, internal security teams and forensic labs. Design partners get early enterprise access and shape the product before general availability, on preferential terms locked in at launch.
CFR is a category distinct from both detection and traditional DFIR. Instead of watching for something that scores as malicious, or reading everything only after a breach is suspected, a CFR platform parses the same deep Windows artifacts a forensic examiner would — on a recurring schedule, before anyone asks. The correlated history therefore already exists at the moment the question arrives.
Three things changed together. Attacks stopped looking like malware — 81% of attack detections in early 2025 involved no malware at all and abuse of built-in binaries grew 126% year over year, so there is nothing for a signature to match. The evidence expires on its own, while median dwell time runs 10 to 14 days and hides intrusions that lasted months. And disclosure clocks are short: GDPR gives 72 hours and the SEC allows 4 business days to determine materiality.
Continuous artifact parsing triggered by the clock rather than an alert; deterministic correlation that threads every record by identity and time rather than scoring it with a model; verifiable evidence where each claim cites its exact source record on a hash-chained, re-walkable log; and complete accounting, so every record lands in a result or a named bucket and absence becomes a finding. A product missing any one of the four is doing collection, triage or detection — not reconstruction.
Not as long as most teams assume. Prefetch and ShimCache cap near 1,024 entries and evict the oldest, the USN journal wraps at roughly 32 MB of ordinary disk activity, and SRUM is pruned by Windows at about 30 days. Event logs roll by size. If collection happens after those windows close, the artifact is simply gone — which is why continuous collection, not faster response, is what preserves it.
Yes. The Crow-Eye forensics engine stays free and open-source under GPL-3.0 for single-machine investigation. Sentinel is the separate enterprise tier for running that same depth across a fleet.
We're keeping the group small and reading every application personally.