Now Available — v1.0

Incident response
starts here.

Arden is a zero-dependency DFIR event log analyzer for Windows. Single executable. 46 detection rules. 14 Sigma rules. Real-time dashboard. Deploy in seconds — no agents, no cloud, no subscriptions.

↓ Download Arden See How It Works
46
Detection Rules
14
Sigma Rules
<30s
Startup Time
0
Dependencies
PowerShell — arden.exe
PS C:\> .\arden.exe --serve
 
╔═════════════════════════════════════════════════╗
ARDEN — DASHBOARD SERVER
╚═════════════════════════════════════════════════╝
 
🌐 Dashboard: http://localhost:8080
📡 API: http://localhost:8080/api/status
 
[*] Reading local event logs...
[*] 6 parallel readers active
[+] Parsed 47,283 events in 28 seconds
[!] 17 CRITICAL23 HIGH • 41 MEDIUM • 12 LOW
[!] COMPOUND RISK: CRITICAL — Active lateral movement detected
46 rules. Every attack phase.
From initial access to impact, Arden covers the full MITRE ATT&CK kill chain with hand-tuned detection rules and self-exclusion logic that minimizes noise.
11
Lateral Movement
RDP, PsExec, WMI, Pass-the-Hash, PS Remoting, Named Pipes, DCOM, Explicit Credentials, Network Logon
8
Defense Evasion
Defender Disabled, Firewall Disabled, Suspicious PS, Log Clearing, Audit Policy, Process Injection, Sysmon Disabled
6
Credential Access
NTLM Auth, Kerberoasting, LSASS Access, DCSync, Comsvcs Dump, SAM Hive Dump
5
Persistence
Scheduled Tasks, Registry, Account Creation, Admin Group Modification, WMI Subscriptions
5
Command & Control
RDP Tunneling, SSH Tunnel Tools, Web Shell Detection, Firewall Loopback, RMM Tool Detection
5
Execution & Escalation
LOLBins, Suspicious Process, BYOVD Drivers, New Services, Special Privilege Assignment
3
Discovery
Admin Group Enumeration, Directory Access, Reconnaissance Commands (net, whoami, ipconfig)
3
Impact
Shadow Copy Deletion, BCDEdit Recovery Disable, Critical Service Termination
Everything you need. Nothing you don't.
Built for solo responders and small teams who need to move fast. No cloud dependency. No license server. No vendor lock-in.
🚀

30-Second Startup

6 parallel PowerShell readers with HashSet filtering parse 50K+ events in under 30 seconds. No indexing, no pre-processing.

📡

Agent Deployment

Push lightweight agents via admin share + WMI. Pull model with heartbeat monitoring. Deploy to your entire network from the dashboard.

🌐

Real-Time Dashboard

Server-Sent Events stream alerts live. Kill chain visualization, dual filtering (host + severity), and full-text search across all fields.

📄

Export & Report

One-click CSV and JSON exports. Filter-aware — exports respect your active severity, tactic, host, and date range filters.

🚫

False Positive Triage

Suppress by rule, rule+host, or rule+user. Reason tracking. Triage dashboard shows what's hidden and why. One-click removal.

🛡

Sigma Rules

14 custom Sigma YAML rules included. Cobalt Strike pipes, Impacket tools, BITS abuse, potato attacks, download cradles, and more.

Three commands. Full visibility.
No installer. No setup wizard. No dependencies to chase. Download, run, investigate.
1

Download

Single portable executable. 15MB. Runs on Windows 10/11, Server 2016+. No .NET, no Python, no runtime needed.

2

Run

arden.exe --serve reads local event logs, runs all 46 detection rules, and launches the dashboard.

3

Investigate

Dashboard opens at localhost:8080. See alerts by severity, filter by host, export findings. Deploy agents to remote machines from the UI.

Why Arden?
Enterprise SIEMs cost six figures and take weeks to deploy. Arden gives you detection coverage in 30 seconds.
Capability Enterprise SIEM Arden
Time to first alert Days to weeks 30 seconds
Dependencies Agent + server + DB + cloud Zero
Deployment Professional services Double-click
Annual cost $50K – $500K+ One-time purchase
Cloud requirement Required Fully offline
MITRE ATT&CK coverage Varies by config 46 rules out of the box
Data leaves your network Yes (telemetry/cloud) Never

Ready to hold the line?

Download Arden and run your first investigation in under a minute. No signup. No telemetry. Your logs stay on your machine.

↓ Download for Windows View on GitHub

Windows 10/11 • Server 2016+ • x64 • ~15MB • No runtime required