How Can We Help?

These pages are available before sign-in. Start with preview access if you are waiting for approval, or jump to collector, evidence, and scanning guides if you already have an account.

Start Here

Preview Access & Sign-In

Learn how manual account approval works, what Google sign-in means, how non-Google users enroll in local MFA, and what to do when an approved account still cannot sign in.

Collector

Run VersionGopherâ„¢

Pick the right signed collector, run local or system scans, capture JSONL, schedule repeat inventory with cron or Windows Task Scheduler, use -m for Miasma incident-response metadata probes, understand hashing, signature evidence, OSV-ready package artifacts, deterministic drift groups, upload results, and what happens while import and background CVE matching finish.

Software Genomics

Groups, Similarity, And Drift

Learn when Groups can support fleet drift detection, when scans should be read as generic software similarity, and how to organize enterprise, small-business, forensic, and one-off upload workflows.

ML/AI

ML/AI Insights Workbench

Learn what each dot represents, how DBSCAN, K-Means, Logistic Regression, and Decision Tree views work, which knobs change the model, how to use the 3D map, and how to turn a hard forensic signal into a concrete analyst action.

Package Risk

OSV, Packages, And Sensitive Artifacts

Understand Package Risk, Package Advisories, Malicious Packages, private-key exposure, crypto-wallet artifacts, and AI prompt-risk findings, including how OSV checks and CVE background matching are updated without confusing them with ordinary NVD/CVE matches.

CVE Accuracy

Actionable, Verify, And Audit Decisions

See how evidence-gated CVE matching uses identity, component scope, version authority, vendor/platform context, and decision traces to reduce visible false positives while preserving audit evidence.

Malware Hash Matching

Trusted Hashes And Malware Hits

Understand how exact SHA-256 matches against the local offline malware hash catalog appear in Malware Hits, file cards, Deep Search, and assessment reports without live reputation lookups during review.

Infrastructure

Cloud, VM, And Offline Guides

Use the Proxmox, VMware, fleet, and offline image workflows when the target cannot install an agent or reach the internet.

Release Notes

What's New

Review the 0.7.6 release: ML/AI Insights, the forensic discovery cockpit, richer PE section and import/export evidence, signed Windows handoff, broader Linux/MIPS/PowerPC collector coverage, evidence-gated CVE accuracy, package risk, hash intelligence, archive detection, and assessment reports.

Roadmap

What's Coming

See the high-level roadmap themes: signature trust enrichment, bounded evidence graphs, analyst annotations, drift baselines, privacy-preserving prevalence, envelope encryption, and case-ready exports.

Analysis

PE, ELF, Archive, And Row Indicators

Understand why VersionGopher preserves PE, Mach-O, ELF, kernel-module, signature, trust-endpoint, and archive context, how result-row indicators work, and how that evidence helps analysts reduce false positives and spot unusual files.