How Can We Help?
These pages are available before sign-in. Start with preview access if you are waiting for approval, or jump to collector, evidence, and scanning guides if you already have an account.
Preview Access & Sign-In
Learn how manual account approval works, what Google sign-in means, how non-Google users enroll in local MFA, and what to do when an approved account still cannot sign in.
Run VersionGopher™
Pick the right signed collector, run local or system scans, capture
JSONL, schedule repeat inventory with cron or Windows Task Scheduler,
use -m for Miasma incident-response metadata probes,
understand hashing, signature evidence, OSV-ready package artifacts,
deterministic drift groups, upload results, and what happens while
import and background CVE matching finish.
Groups, Similarity, And Drift
Learn when Groups can support fleet drift detection, when scans should be read as generic software similarity, and how to organize enterprise, small-business, forensic, and one-off upload workflows.
OSV, Packages, And Sensitive Artifacts
Understand Package Risk, Package Advisories, Malicious Packages, private-key exposure, crypto-wallet artifacts, and AI prompt-risk findings, including how OSV checks and CVE background matching are updated without confusing them with ordinary NVD/CVE matches.
Cloud, VM, And Offline Guides
Use the Proxmox, VMware, fleet, and offline image workflows when the target cannot install an agent or reach the internet.
What's New
Review the 0.7.5 release: signed collectors, Miasma response
workflows with -m metadata probes, signature/provenance evidence, measured import
improvements, component-scoped CVE accuracy, package risk, security
feeds, archive detection, AI prompt-risk detection, PE duplicate-row
guidance for older scans, and binary forensics.
What's Coming
See the high-level roadmap themes: trust enrichment, software-genome graph views, local package-advisory intelligence, protected evidence, encrypted-import performance work, fleet drift, and enterprise workflow polish.
PE, ELF, Archive, And Row Indicators
Understand why VersionGopher preserves PE, Mach-O, ELF, kernel-module, signature, trust-endpoint, and archive context, how result-row indicators work, and how that evidence helps analysts reduce false positives and spot unusual files.