Resurge watches every protected file in real time, isolates the process behind a drift the instant it starts, and restores exactly what it touched — while keeping every high-risk action locked behind your explicit approval, never a silent judgment call.
Most tools tell you something went wrong. Resurge isolates the cause, verifies your backup is actually clean, and restores — before an incident report is even the first thing you see.
SHA-256 differential hashing tracks drift against a continuously updated baseline — not a one-time-trained model that goes stale the day it's built.
The malicious process is confirmed dead and the backup candidate is scanned for dormant malware before a single file is restored, never the reverse.
Every action is hash-chained, signed, and anchored to a separate service an attacker's database access can't reach — so blinding the SOC first doesn't work.
Each layer runs independently. Together they cover the moment someone logs in, the plain read no file-watcher can see, and the encryption itself.
Every login is scored on device fingerprint, IP reputation, and timing — including Haversine-based impossible-travel detection, so a credential used from two continents in ten minutes is caught before it's trusted.
Auth-time · zero footprint on the endpointKeystroke and interaction dynamics build a profile of how your team actually works — so a valid session behaving like someone else raises its risk score, not just its login.
Continuous, passiveRealistic decoy files, watched by three independent channels at once — including Windows Security-audit event tracking, the only one of the three that catches a plain read that never creates, deletes, or renames anything.
Live-tested against real Windows targetsThe baseline every deployment runs: entropy and hash-based drift detection, isolate-confirm-scan-restore, and a circuit breaker that halts and escalates the moment a burst of changes exceeds a threshold you set.
Always on · foundation for every pilotResurge acts fast on what's reversible, and stops cold at what isn't. Nothing — including its own reasoning layer — can downgrade a high-risk action to something it can approve itself.
Blocking a live connection, killing a persistence mechanism, suspending a process — executed immediately, reversible, visible in the audit log the instant it happens.
Revoking credentials or rotating a secret waits for an explicit human decision. Nothing about the action changes while it waits — not even the file it targets.
An unapproved high-risk action that times out is rejected and logged. It never falls back to a different automated action — a timeout is not a quieter form of approval.
Trust. Control. Resilience. — the boundary between what Resurge does on its own and what it asks you first is never ambiguous, in the interface or in the code.
Version 0.1.0 · free during early access