Reaper: respond from somewhere clean.
A dedicated incident response and threat hunting workspace for your team, deployed rapidly outside your network.
Out of band means separate hosting, sign-in and communications, so your team can coordinate without relying on systems an attacker may control.
Keep your response separate from affected systems.
If an intruder is in your email or admin accounts, investigating from those systems can tip them off.
Separate
Independent of your email, sign-in and network.
Fast
The whole platform is built in one deployment.
Temporary
Retired when the case closes, after the agreed evidence handover.
Built on tools responders already trust.
Proven open-source applications used by incident response teams worldwide, joined behind one secure sign-in.
- VelociraptorCollect evidence and hunt across your computers.
- OpenSearchSearch the logs and records collected for the case.
- ArkimeInvestigate captured network traffic.
- DFIR-IRISTrack the case timeline, tasks and evidence.
- MISPCheck evidence against known threat intelligence.
- MattermostA private channel for the response team.
- AuthentikOne sign-in and access control across every tool.
- AI-assisted triageOptional, read-only help querying the evidence.
A dedicated workspace for each case.
We set up the applications, secure sign-in and team access. Together, we agree how evidence will be collected from your systems.
Systems under investigation
- Email and sign-in accounts
- Computers and servers
- Network and cloud logs
Potentially compromised systems under review.
Your private case platform
- Evidence store and search
- Endpoint and network investigation
- Case management
- Responder chat
A separate platform for each case.
- 01DeployThe full platform, built fresh.
- 02CollectAuthorised evidence only.
- 03InvestigateYour team hunts and builds the timeline.
- 04RetireExport what you need, then remove.
- Runs on a single machine, and scales by adding capacity
- Can be installed fully offline
- Encrypted connections and separate access controls
- Start small and add tools as the case grows
Before you begin
Is Reaper a 24/7 emergency service?
No. Reaper is a platform for your team to use. Arranging it in advance means it’s ready faster when you need it.
Does Reaper connect into our network?
Only through collection paths you authorise. Evidence flows out to Reaper; there is no general route back in.
Is our evidence kept separate?
Yes. Every case gets its own platform, storage and credentials.
Who runs the investigation?
Your team, or the responders you choose. We provide the platform.
What happens to the data afterwards?
We agree what evidence you need to keep and how it will be handed over. The platform and its data are then removed under those arrangements.
Does it replace our IT provider or monitoring?
No. It gives your responders a separate workspace during an incident. Confirmed incidents can also be reported through ReportCyber.
Know who to call before you need them.
Tell us what you need to protect, and we’ll agree how Reaper would be deployed for you.