Log Evidence
Reviews Security and System events for failed logons, account changes, suspicious sessions, and investigation windows that matter.
DENSHI PROSecurity Operations CenterDENSHI PRO
DENSHI PRO helps you review live Windows evidence, prioritize risk, control network-active processes, build an evidence timeline, and apply rollback-aware hardening from one local operator console.
Common warning signs
What DENSHI PRO checks
DENSHI PRO does not ask you to trust a vague score. It separates evidence, exposure, hardening, and containment so each action can be reviewed before it changes the machine.
Reviews Security and System events for failed logons, account changes, suspicious sessions, and investigation windows that matter.
Checks Run and RunOnce startup locations, then reports executable paths and signature status so unknown launch points stand out.
Maps listeners and active connections back to process owners, then gives operators a safer path to block apps or close selected exposure.
Merges sessions, connections, startup clues, file-access indicators, and DENSHI actions into one readable storyline.
Audits terminal sessions and can optionally terminate non-whitelisted sessions when an operator explicitly enables enforcement.
Applies Basic, Balanced, or Aggressive hardening profiles with managed snapshots so controls can be restored later.
How to use it
Start DENSHI PRO on the Windows machine you are worried about. No cloud account is required.
See event logs, persistence points, sessions, listeners, process owners, vulnerabilities, and collector status in one place.
Select exact sessions, ports, processes, and network-active apps before applying the smallest useful control.
Run the audit again, review the evidence timeline, and use Echo when you need a network-side view.
Product screenshots
The interface is built for security work: quick overview first, then deeper pages for logs, process trust, network control, listeners, evidence timelines, vulnerability hardening, and recovery.
A plain-English summary of what the scan found, what it did not prove, and what to review next.
Successful logons, failed logons, account creation events, and routine versus interesting patterns.
Run and RunOnce startup entries with executable paths, disk presence, and signature context.
Active Windows sessions, protected operator sessions, and whitelist-based enforcement status.
Open listeners, exposed interfaces, owning processes, and review-first socket findings.
Preset hardening levels, individual controls, preview, apply, enforce, restore, and managed rollback.
Hardening without guessing
When you are worried about compromise, random cleanup can make things worse. DENSHI PRO focuses on understandable controls and managed restore points so defensive changes stay deliberate, reviewable, and reversible.
Review inbound exposure and restore a known-good local firewall posture.
Reduce legacy file-sharing risk without guessing which modern services are in use.
Limit removable-media and launch behavior that attackers often abuse for persistence.
Close a common weak account path while keeping the change easy to verify.
Capture more useful PowerShell evidence for later review and incident notes.
Record interactive command activity when you need a stronger audit trail.
Operator manual
The manual explains the updated SOC workflow, audit stages, network control, incident containment, evidence timeline, vulnerability hardening, and safe recovery model included with version 1.1.0.
Companion tool
DENSHI PRO inspects the inside of the Windows machine, while Echo views it from the outside: scanning hosts, open ports, running services, and overall network exposure.
You should review these findings before concluding that a machine is clean. Echo is a lightweight port scanner that identifies open ports across your network.
Echo scan
FAQ
Run a local triage tool that reviews Windows event logs, suspicious logins, startup persistence, active sessions, listening ports, network-active processes, vulnerabilities, and security settings. DENSHI PRO organizes those checks into evidence you can review.
No. DENSHI PRO is positioned as a local Windows tool. Scan results and exported reports stay under your control unless you choose to share them.
DENSHI PRO checks suspicious logins, account changes, startup entries, listening sockets, terminal sessions, network-active process owners, exfiltration clues, vulnerability evidence, collector errors, and hardening status.
DENSHI PRO includes rollback-aware hardening and precision incident controls so changes can be reviewed, verified, and restored instead of applying random cleanup blindly.
Built by Mando
This project is for home users, small teams, and operators who need a clear first look at a Windows system without sending private scan data into a hosted dashboard.

Builder of local-first tools for investigation, audit, and defense.
Start the check
Use DENSHI PRO when you need to understand what happened on a Windows machine, what is exposed right now, and which control is safest to apply.