DENSHI PRO

Security Operations Center for Windows.

DENSHI PRO helps you review live Windows evidence, prioritize risk, control network-active processes, build an evidence timeline, and apply rollback-aware hardening from one local operator console.

LocalRuns on your Windows systemNo accountNo dashboard login requiredControlBlock or contain exact exposureManualDetailed operator guide included

Common warning signs

  • Unexpected logins or account changes
  • Unknown programs starting with Windows
  • Open ports you cannot explain
  • Suspicious sessions or remote access

What DENSHI PRO checks

Turn suspicion into an operator-ready queue.

DENSHI PRO does not ask you to trust a vague score. It separates evidence, exposure, hardening, and containment so each action can be reviewed before it changes the machine.

Log Evidence

Reviews Security and System events for failed logons, account changes, suspicious sessions, and investigation windows that matter.

Persistence

Checks Run and RunOnce startup locations, then reports executable paths and signature status so unknown launch points stand out.

Live Network Control

Maps listeners and active connections back to process owners, then gives operators a safer path to block apps or close selected exposure.

Evidence Timeline

Merges sessions, connections, startup clues, file-access indicators, and DENSHI actions into one readable storyline.

Sessions

Audits terminal sessions and can optionally terminate non-whitelisted sessions when an operator explicitly enables enforcement.

Hardening

Applies Basic, Balanced, or Aggressive hardening profiles with managed snapshots so controls can be restored later.

How to use it

A practical path when something feels wrong.

01

Run a local check

Start DENSHI PRO on the Windows machine you are worried about. No cloud account is required.

02

Review the evidence

See event logs, persistence points, sessions, listeners, process owners, vulnerabilities, and collector status in one place.

03

Contain precisely

Select exact sessions, ports, processes, and network-active apps before applying the smallest useful control.

04

Verify exposure

Run the audit again, review the evidence timeline, and use Echo when you need a network-side view.

Product screenshots

See the operator screens before you download.

The interface is built for security work: quick overview first, then deeper pages for logs, process trust, network control, listeners, evidence timelines, vulnerability hardening, and recovery.

Executive overview

A plain-English summary of what the scan found, what it did not prove, and what to review next.

Event log review

Successful logons, failed logons, account creation events, and routine versus interesting patterns.

Startup persistence

Run and RunOnce startup entries with executable paths, disk presence, and signature context.

Session audit

Active Windows sessions, protected operator sessions, and whitelist-based enforcement status.

Listening sockets

Open listeners, exposed interfaces, owning processes, and review-first socket findings.

Hardening controls

Preset hardening levels, individual controls, preview, apply, enforce, restore, and managed rollback.

Hardening without guessing

Fix carefully, with rollback in mind.

When you are worried about compromise, random cleanup can make things worse. DENSHI PRO focuses on understandable controls and managed restore points so defensive changes stay deliberate, reviewable, and reversible.

Windows Firewall baseline

Review inbound exposure and restore a known-good local firewall posture.

SMBv1 disabled

Reduce legacy file-sharing risk without guessing which modern services are in use.

AutoRun reduced

Limit removable-media and launch behavior that attackers often abuse for persistence.

Guest account disabled

Close a common weak account path while keeping the change easy to verify.

PowerShell script block logging

Capture more useful PowerShell evidence for later review and incident notes.

Optional PowerShell transcription

Record interactive command activity when you need a stronger audit trail.

Operator manual

Use the updated guide while you investigate.

The manual explains the updated SOC workflow, audit stages, network control, incident containment, evidence timeline, vulnerability hardening, and safe recovery model included with version 1.1.0.

Companion tool

Echo checks what is visible on the network.

DENSHI PRO inspects the inside of the Windows machine, while Echo views it from the outside: scanning hosts, open ports, running services, and overall network exposure.

You should review these findings before concluding that a machine is clean. Echo is a lightweight port scanner that identifies open ports across your network.

Host discoveryOpen port reviewService hintsExposure notes
Download Echo for Windows

Echo scan

Network exposure review

FAQ

Questions people ask when they think they were hacked.

How can I check if I've been hacked on Windows?

Run a local triage tool that reviews Windows event logs, suspicious logins, startup persistence, active sessions, listening ports, network-active processes, vulnerabilities, and security settings. DENSHI PRO organizes those checks into evidence you can review.

Does Denshi upload my scan results?

No. DENSHI PRO is positioned as a local Windows tool. Scan results and exported reports stay under your control unless you choose to share them.

What signs of compromise does Denshi look for?

DENSHI PRO checks suspicious logins, account changes, startup entries, listening sockets, terminal sessions, network-active process owners, exfiltration clues, vulnerability evidence, collector errors, and hardening status.

Can Denshi fix security settings?

DENSHI PRO includes rollback-aware hardening and precision incident controls so changes can be reviewed, verified, and restored instead of applying random cleanup blindly.

Built by Mando

Local-first tools for people who want answers.

This project is for home users, small teams, and operators who need a clear first look at a Windows system without sending private scan data into a hosted dashboard.

Mando portrait

Mando

Builder of local-first tools for investigation, audit, and defense.

Start the check

Download DENSHI PRO for Windows.

Use DENSHI PRO when you need to understand what happened on a Windows machine, what is exposed right now, and which control is safest to apply.