How Can We Help?
These pages are available before sign-in. Start with preview access if you are waiting for approval, or jump to collector, evidence, and scanning guides if you already have an account.
Preview Access & Sign-In
Learn how manual account approval works, what Google sign-in means, how non-Google users enroll in local MFA, and what to do when an approved account still cannot sign in.
Run VersionGopherâ„¢
Pick the right signed collector, run local or system scans, capture
JSONL, schedule repeat inventory with cron or Windows Task Scheduler,
use -m for Miasma incident-response metadata probes,
understand hashing, signature evidence, OSV-ready package artifacts,
deterministic drift groups, upload results, and what happens while
import and background CVE matching finish.
Standalone MSI, Tray, And Intune
Install locally or deploy through Microsoft Intune. Configure whole-system or bounded directory profiles in Fleet or the tray, review the actual collector command, enroll with a one-use bootstrap, and verify policy convergence without editing ProgramData files.
Baselines, Similarity, And Drift
Designate, approve, compare, and retire trusted scan baselines through the scoped administrator API. Learn when Groups support fleet drift, when evidence means only generic similarity, and how to keep comparison inputs repeatable.
ML/AI Insights Workbench
Start with the deterministic operational brief and reviewed Top oddities examples, then learn what each dot represents, how the discovery and prediction models work, which knobs change the model, and how to turn a forensic signal into a concrete analyst action.
OSV, Packages, And Sensitive Artifacts
Understand Package Risk, Package Advisories, Malicious Packages, private-key exposure, crypto-wallet artifacts, and AI prompt-risk findings, including how OSV checks and CVE background matching are updated without confusing them with ordinary NVD/CVE matches.
Actionable, Verify, And Audit Decisions
See how evidence-gated CVE matching uses identity, component scope, version authority, vendor/platform context, and decision traces to reduce visible false positives while preserving audit evidence.
Trusted Hashes And Malware Hits
Understand how exact SHA-256 matches against the local offline malware hash catalog appear in Malware Hits, file cards, Deep Search, and assessment reports without live reputation lookups during review.
Cloud, VM, And Offline Guides
Use the Proxmox, VMware, fleet, and offline image workflows when the target cannot install an agent or reach the internet.
What's New
Review 0.7.19: bounded whole-system or directory scan profiles, an exact effective collector-command preview, guardrails against empty or impossible schedules, all-or-selected policy delivery, and remotely repairable unavailable targets.
What's Coming
See the high-level product direction for cross-platform managed collection, embedded and mission portability, software-evidence context, adaptive analysis, protected evidence, and integrations.
PE, ELF, Archive, And Row Indicators
Understand why VersionGopher preserves PE, Mach-O, ELF, kernel-module, signature, trust-endpoint, and archive context, how result-row indicators work, and how that evidence helps analysts reduce false positives and spot unusual files.