Find one artifact. Hunt the entire network. Map the kill chain. No EDR agents. No complex deployments. Just SMB, WMI, YAML rules, and YARA — phasing through your infrastructure like a ghost.
WRAITH phases through your network unseen — no agents installed, no footprint left behind. Just intelligence.
Phase through file shares across entire subnets. Hunt for known-bad paths, filenames, and hashes using declarative YAML rules. Wildcard user profile expansion built in.
AGENTLESSQuery running processes, services, scheduled tasks, autoruns, and registry keys remotely via WMI/DCOM. Catch LOLBins, persistence, and suspicious services without touching the endpoint.
PROCESSES · SERVICES · TASKSDownload suspicious artifacts and scan them locally with compiled YARA rulesets. Ship with rules for Mimikatz, Cobalt Strike, SharpHound, encoded PowerShell, and more.
7 RULES INCLUDEDEvery hunt rule tags tactic, technique, and subtechnique. Findings carry ATT&CK context through to every export format — from JSON to HTML reports to Sentinel.
TACTIC · TECHNIQUE · SUBGenerate IOC CSVs formatted for the Microsoft Sentinel Threat Intelligence upload connector. Full metadata (TLP, confidence, expiry, MITRE tags) or simple two-column format.
CSV · SENTINEL · IOCStandalone HTML reports with severity breakdown, host summary, ATT&CK coverage heatmap, and full findings table. Dark-themed. No dependencies. Just open in a browser.
HTML · JSON · JSONLSee WRAITH sweep a network in real time. Choose a scenario below.
┌─────────────────────────────────────────────────────────────────┐ │ WRAITH ENGINE │ │ │ │ YAML Rules ──→ Parser ──→ Matcher ──→ Findings │ │ │ ↑ │ │ │ ▼ │ ▼ │ │ Collectors │ Exporters │ │ ├── SMB (port 445) ──────────┤ ├── JSON │ │ ├── WMI (port 135) ──────────┤ ├── Sentinel CSV │ │ └── YARA (local scan) ────────┘ └── HTML Report │ │ │ │ Target Expansion ──→ Port Discovery ──→ Thread Pool │ │ CIDR / IP / @file 445 + 135 40 concurrent │ └─────────────────────────────────────────────────────────────────┘
Three commands. No signup. No license. MIT open source.
You found one artifact. WRAITH finds the rest. Open source, agentless, and ready to haunt your adversaries.