How Can We Help?

These pages are available before sign-in. Start with preview access if you are waiting for approval, or jump to collector, evidence, and scanning guides if you already have an account.

Start Here

Preview Access & Sign-In

Learn how manual account approval works, what Google sign-in means, how non-Google users enroll in local MFA, and what to do when an approved account still cannot sign in.

Collector

Run VersionGopherâ„¢

Pick the right signed collector, run local or system scans, capture JSONL, schedule repeat inventory with cron or Windows Task Scheduler, use -m for Miasma incident-response metadata probes, understand hashing, signature evidence, OSV-ready package artifacts, deterministic drift groups, upload results, and what happens while import and background CVE matching finish.

Windows Endpoints

Standalone MSI, Tray, And Intune

Install locally or deploy through Microsoft Intune. Configure whole-system or bounded directory profiles in Fleet or the tray, review the actual collector command, enroll with a one-use bootstrap, and verify policy convergence without editing ProgramData files.

Software Genomics

Baselines, Similarity, And Drift

Designate, approve, compare, and retire trusted scan baselines through the scoped administrator API. Learn when Groups support fleet drift, when evidence means only generic similarity, and how to keep comparison inputs repeatable.

ML/AI

ML/AI Insights Workbench

Start with the deterministic operational brief and reviewed Top oddities examples, then learn what each dot represents, how the discovery and prediction models work, which knobs change the model, and how to turn a forensic signal into a concrete analyst action.

Package Risk

OSV, Packages, And Sensitive Artifacts

Understand Package Risk, Package Advisories, Malicious Packages, private-key exposure, crypto-wallet artifacts, and AI prompt-risk findings, including how OSV checks and CVE background matching are updated without confusing them with ordinary NVD/CVE matches.

CVE Accuracy

Actionable, Verify, And Audit Decisions

See how evidence-gated CVE matching uses identity, component scope, version authority, vendor/platform context, and decision traces to reduce visible false positives while preserving audit evidence.

Malware Hash Matching

Trusted Hashes And Malware Hits

Understand how exact SHA-256 matches against the local offline malware hash catalog appear in Malware Hits, file cards, Deep Search, and assessment reports without live reputation lookups during review.

Infrastructure

Cloud, VM, And Offline Guides

Use the Proxmox, VMware, fleet, and offline image workflows when the target cannot install an agent or reach the internet.

Release Notes

What's New

Review 0.7.19: bounded whole-system or directory scan profiles, an exact effective collector-command preview, guardrails against empty or impossible schedules, all-or-selected policy delivery, and remotely repairable unavailable targets.

Roadmap

What's Coming

See the high-level product direction for cross-platform managed collection, embedded and mission portability, software-evidence context, adaptive analysis, protected evidence, and integrations.

Analysis

PE, ELF, Archive, And Row Indicators

Understand why VersionGopher preserves PE, Mach-O, ELF, kernel-module, signature, trust-endpoint, and archive context, how result-row indicators work, and how that evidence helps analysts reduce false positives and spot unusual files.