Athar Sec Talk to us

أثرAthar · the trace left behind

Every intrusion leaves a trace.

Athar Sec builds two products for the defenders who follow it. QSentry stands sentinel over your network. TraceMind reads the evidence on your machines and explains what happened, citing every source.

  • TraceMind: QRDI-awarded research
  • Founded by a practicing SOC analyst
  • Built in Qatar
QSentry and TraceMind at workThree detection rings sweep a field of network activity. When the sweep finds something, TraceMind links a network flow, two Windows events and an ATT&CK technique into one trace that ends at the core.SIGNATURESMACHINE LEARNINGQUANTUMFLOW 10.0.4.17 → :445EVTX 4624 · NETWORK LOGONEVTX 7045 · SERVICE INSTALLEDT1021.002 · LATERAL MOVEMENTTRACE FOUNDQSENTRY · WATCHTRACEMIND · TRACE

The problem

Attackers count on noise.

Security teams drown in alerts while the real story sits in evidence nobody has time to read.

Alert 4471 · no evidence

Alerts arrive without proof.

Analysts re-investigate each detection by hand because the traffic behind it was never kept.

Sensor 07 · 0 events

Silence passes for safety.

No alert can mean no attack, or no data. Most tools can't tell you which.

AI answer · 0 citations

AI fills the gaps with guesses.

A language model will describe an attack the logs never recorded, in confident, fluent prose.

The platform

Two products. One trace.

QSentry, our NDR, catches the first sign of an intrusion on the wire. TraceMind, our path to XDR, follows it into the machines it touched and writes down what it finds, with sources.

QSentry

NDR · the quantum sentry

A sentinel with three lines of watch.

QSentry is network detection and response built in layers. It reads live traffic and judges every flow. When the classical model is unsure, a quantum classifier takes a second look before anything is waved through.

  1. L1SignaturesMore than 48,000 rules catch known attacks the moment they appear.
  2. L2Machine learningA model trained on flow behavior flags what signatures miss.
  3. L3Quantum classifierConsulted only when the classical model's confidence drops.

Working prototype · sub-second alerts in lab tests

LIVE TRAFFICL1SIGNATURESL2ML MODELL3QUANTUMSMB · 445KNOWN ATTACKDNS · 53UNUSUAL PATTERNTLS · 443UNSURE2ND LOOK · FLAGGEDHTTPS · 443CLEAN · LOGGED
Four flows meet three layers. Every alert keeps the flow behind it, so analysts check evidence instead of starting over.

TraceMind

XDR · the mind that finds the trace

An investigator that cites its sources.

TraceMind reads the artifacts Windows leaves behind, rebuilds the timeline and explains what happened in plain language. Every sentence links back to the file and record it came from. When the evidence isn't there, it says so.

Today it works from endpoint evidence. Next it takes in QSentry's view of the network and grows into a full XDR.

Reads the evidence
Event logs, registry hives, Prefetch, MFT, Shimcache, Amcache, USN Journal and SRUM.
Rebuilds the timeline
Every artifact merged into one ordered account of the incident.
Speaks ATT&CK
Findings arrive mapped to MITRE ATT&CK techniques, with their indicators.
Answers in plain language
Ask about the case. Get cited answers and a report you can hand over.

QRDI-awarded research · event-log pipeline running

EVTXREGISTRYMFTAMCACHEPREFETCHT1021.0023 CITATIONSCITES EVTX 4624, 7045CITES PSEXESVC PREFETCH
Artifacts in, findings out. Each finding points back to the records that support it.

How it works

From the first packet to the final report.

  1. Watch

    QSentry flags a suspicious flow and keeps the traffic behind it.

    alert + traffic
  2. Collect

    Artifacts are gathered from the machines that flow touched.

    host artifacts
  3. Reason

    TraceMind rebuilds the timeline and drafts findings, each tied to its sources.

    cited findings
  4. Decide

    An analyst reviews the evidence and approves. Nothing closes on its own.

QSentry and TraceMind run as separate products today. Next on our roadmap: one case file across network and endpoint, as TraceMind grows into XDR.

Show your work

Every finding opens onto its evidence.

This is the standard we hold TraceMind to. Claims link to records, and missing evidence is called out by name.

TraceMind · Case ATH-0142 · Host FIN-WS07Illustrative example

Timeline · Qatar time

  1. EVTX 4624

    Network logon, type 3, from 10.0.4.17

  2. EVTX 7045

    Service installed: PSEXESVC

  3. Prefetch

    PSEXESVC.EXE runs for the first time

  4. EVTX 1102

    Security log cleared

Findings

Lateral movement over SMB

T1021.002 Supported
EVTX 4624 #18420EVTX 7045 #2291PSEXESVC.EXE-AD70A45F.pf

Logs cleared to hide activity

T1070.001 Supported
EVTX 1102 #18977

Data taken off the machine

TA0010 Not enough evidence

No outbound traffic records were collected for FIN-WS07. Add the firewall logs to test this.

Analyst

Did they take any data?

TraceMind

I can't tell yet. Outbound traffic for FIN-WS07 wasn't collected, so its absence proves nothing. Add the firewall logs for 02:00 to 03:00 and I'll check again.

2 of 3 findings supported · awaiting analyst approvalExample data, not from a real customer

About us

Built by defenders, in Qatar.

Athar Sec brings frontline SOC experience together with QRDI-awarded research in AI forensics. We build for the analyst who has to stand behind every case they close.

Evidence first
If a claim can't point to a record, it doesn't ship.
Defense only
We build for defenders, and our tools run only where the owner has authorized them.
People decide
Our tools recommend. Analysts approve.
Rooted in Qatar
Built here, for the security teams of Qatar and the Gulf.

أثر

atharArabic · noun

  1. A trace; the mark something leaves behind.
  2. An effect or an impact.

Plural آثار āthār: traces, remains, antiquities.

Design partners

From traces to a safer tomorrow.

We're opening early access to a small group of design partners: SOC teams, managed security providers and forensic investigators in Qatar and the Gulf.

Or write to founder@atharsec.com

People · Privacy · Progress