Evidence-first endpoint intelligence

Start with the problem.

PC Investigator investigates endpoint problems without requiring them to match a predefined detector. It gathers evidence, follows promising leads, requests what is missing, and shows what the evidence actually supports.

Read-only by default
Windows · macOS · Linux
Self-host or managed
app.pcinvestigator.dev
Fleet DashboardInvestigations across your fleet
WD
ENDPOINTS42Managed fleet
ONLINE41Reporting now
IN REVIEW4Open investigations
FOLLOW-UP1Needs more evidence
Investigation QueueActive endpoint inquiries
View all
FOLLOW-UP
WS-042Additional evidence requested
4m
IN REVIEW
DESKTOP-18Endpoint behavior under investigation
18m
EVIDENCE
SERVER-31New endpoint evidence available
37m
Fleet CoverageInvestigation readiness
88%Reporting
37 reporting4 in review1 follow-up
EndpointsCurrent fleet status
ENDPOINTSTATUSOSINVESTIGATIONLAST SEEN
MAC-042● OnlinemacOSReadyNow
WIN-042● OnlineWindows 11In reviewNow
THE INVESTIGATION LAYER

Alerts tell you what happened.
PC Investigator helps determine why.

01CollectEndpoint telemetry
02CorrelateEvidence & history
03InvestigateTest hypotheses
04Follow upGather what is missing
A DIFFERENT KIND OF ENDPOINT TOOL

Built for investigation, not alert overload.

Start with the issue in front of you. PC Investigator gathers evidence, follows leads, tests hypotheses, and keeps uncertainty visible until the evidence supports an answer.

INVESTIGATING
Endpoint behavior under investigationWIN-042 · Windows 11
STATUSOPEN
FINDING SUMMARY

An endpoint issue was reported. PC Investigator collected the initial evidence, identified unanswered questions, and requested targeted read-only telemetry to distinguish the remaining hypotheses.

InvestigationIN PROGRESS
Root causeNot established
EvidenceExpanding
ESTABLISHED EVIDENCE
  • Reported behavior anchored to a time window
  • Current endpoint state collected
  • Relevant historical evidence correlated
CAUSES / LIMITS
  • No single cause is established yet
  • Correlation is kept separate from causation
  • Missing evidence remains explicit
NEXT DIAGNOSTIC
Recommended Collect the evidence most likely to distinguish the remaining hypotheses.
FOLLOW-UP EVIDENCERequested from endpoint
01

Evidence-backed investigations

Correlate endpoint events, system state, and historical findings instead of forcing technicians to sift through raw logs.

Evidence ≠ hypothesis
02

AI-assisted reasoning

Use your preferred model to reason over normalized evidence, test competing explanations, and decide what information would reduce uncertainty next.

Evidence drives the investigation
03

Governed diagnostics

Collect additional evidence remotely through named read-only capabilities, bounded execution, and auditable results.

Human control stays in the loop
FROM QUESTION TO EVIDENCE

Give every technician a repeatable way to investigate the unknown.

PC Investigator starts with the reported behavior, builds an evidence package, tests competing explanations, and gathers more information when the answer is not yet supported.

1
Start with the question

Investigate the behavior or concern without requiring a predefined problem category.

2
Build the evidence

Deterministic collectors normalize facts without deciding in advance what problem they represent.

3
Test the hypotheses

AI reasons across the evidence, challenges its own explanations, and identifies what is still missing.

4
Follow the evidence

Approved read-only capabilities gather targeted follow-up data; privileged actions remain under human control.

Investigation timeline
WIN-042
Investigation openedReported behavior and time window captured
Initial evidence collectedEndpoint state · events · history
Follow-up requestedAdditional read-only evidence needed
Agent returned evidenceTargeted capability completed
Hypotheses reassessedUnsupported explanations discarded
Root cause statusNot establishedPC Investigator preserves uncertainty instead of inventing certainty.
CROSS-PLATFORM BY DESIGN

One investigation model. Every endpoint.

Use a common investigative workflow across mixed fleets while preserving platform-specific evidence.

Windows

Platform-aware system, event, process, service, network, hardware, and historical evidence for open-ended investigation.

SUPPORTED

macOS

Platform-aware system, log, process, service, network, hardware, and historical evidence for the same investigative workflow.

SUPPORTED

Linux

A growing set of platform-native collectors built around the same evidence-first investigation model.

FOUNDATION
DEPLOY IT YOUR WAY

Your infrastructure.
Your AI.
Your data.

Run PC Investigator where your organization needs it. Start self-hosted today, with managed deployment options planned as the platform matures.

Container-first HubDocker today. Kubernetes-ready architecture.
Bring your own modelOpenAI today, provider abstraction built for more.
Outbound endpoint connectivityNo inbound firewall holes required for agents.
PC INVESTIGATOR ARCHITECTURELIVE DESIGN
Windows
macOS
Linux
Outbound TLS
PC Investigator HubInventory · Evidence · Policy · Audit
Curated evidence
AI ProviderBYO model & key
DatabaseSQLite / PostgreSQL
CONTROL BEFORE AUTOMATION

Designed to investigate safely.

The agent should be powerful enough to answer hard questions—not powerful enough to bypass your controls.

01

Read-only by default

Collection and investigation are designed around evidence gathering before remediation.

02

Allowlisted diagnostics

Remote commands are cataloged actions rather than arbitrary shell access.

03

Human approval

Privileged remediation is designed to require explicit policy and technician approval.

04

Auditable actions

Enrollment, investigations, commands, and future remediation flows are built around traceability.

Security is a product requirement, not a marketing badge.PC Investigator is under active development. We do not claim certifications or compliance attestations the product has not earned.
PC INVESTIGATOR EARLY ACCESS

Spend less time proving what isn't wrong.

Join the early-access list for product updates, self-hosted previews, and opportunities to help shape the investigation workflow.

No spam. Early-access contact only.