Alerts arrive without proof.
Analysts re-investigate each detection by hand because the traffic behind it was never kept.
أثرAthar · the trace left behind
Athar Sec builds two products for the defenders who follow it. QSentry stands sentinel over your network. TraceMind reads the evidence on your machines and explains what happened, citing every source.
The problem
Security teams drown in alerts while the real story sits in evidence nobody has time to read.
Analysts re-investigate each detection by hand because the traffic behind it was never kept.
No alert can mean no attack, or no data. Most tools can't tell you which.
A language model will describe an attack the logs never recorded, in confident, fluent prose.
The platform
QSentry, our NDR, catches the first sign of an intrusion on the wire. TraceMind, our path to XDR, follows it into the machines it touched and writes down what it finds, with sources.
NDR · the quantum sentry
A sentinel with three lines of watch.
QSentry is network detection and response built in layers. It reads live traffic and judges every flow. When the classical model is unsure, a quantum classifier takes a second look before anything is waved through.
Working prototype · sub-second alerts in lab tests
XDR · the mind that finds the trace
An investigator that cites its sources.
TraceMind reads the artifacts Windows leaves behind, rebuilds the timeline and explains what happened in plain language. Every sentence links back to the file and record it came from. When the evidence isn't there, it says so.
Today it works from endpoint evidence. Next it takes in QSentry's view of the network and grows into a full XDR.
QRDI-awarded research · event-log pipeline running
How it works
QSentry flags a suspicious flow and keeps the traffic behind it.
alert + trafficArtifacts are gathered from the machines that flow touched.
host artifactsTraceMind rebuilds the timeline and drafts findings, each tied to its sources.
cited findingsAn analyst reviews the evidence and approves. Nothing closes on its own.
QSentry and TraceMind run as separate products today. Next on our roadmap: one case file across network and endpoint, as TraceMind grows into XDR.
Show your work
This is the standard we hold TraceMind to. Claims link to records, and missing evidence is called out by name.
Timeline · Qatar time
Network logon, type 3, from 10.0.4.17
Service installed: PSEXESVC
PSEXESVC.EXE runs for the first time
Security log cleared
Findings
No outbound traffic records were collected for FIN-WS07. Add the firewall logs to test this.
Did they take any data?
I can't tell yet. Outbound traffic for FIN-WS07 wasn't collected, so its absence proves nothing. Add the firewall logs for 02:00 to 03:00 and I'll check again.
About us
Athar Sec brings frontline SOC experience together with QRDI-awarded research in AI forensics. We build for the analyst who has to stand behind every case they close.
أثر
atharArabic · noun
Plural آثار āthār: traces, remains, antiquities.
Design partners
We're opening early access to a small group of design partners: SOC teams, managed security providers and forensic investigators in Qatar and the Gulf.
Or write to founder@atharsec.com
People · Privacy · Progress