DarkHorse InfoSec

HADES

Hidden Artifact Detection & EXIF Scanner - Enterprise Metadata Forensics Engine

PRODUCTION-READY | v1.7.1 GA

Court-ready metadata forensics for security teams, incident responders, and SOC operations. Zero-execution analysis, never runs target files.

19,882 Files in Validation Run
99.98% Detection (Contagio, 11,877)
99.93% Overall Malware Detection (15,156)
51 MITRE Techniques
144 YARA Rules
20 Forensic Analyzer Modules

Measured 2026-09-13 on engine source at commit de6bf83f (v1.7.1 plus unreleased detection changes), with threat intelligence enabled. Malware sample composition: MalwareBazaar 3,269 (99.72% detection) · Contagio 11,877 (99.98%) · targeted Gootloader 10 (100%). Overall malware detection: 99.93% across 15,156 samples, 10 undetected, 1 timeout. A 4,726-file clean corpus was scanned the same day: 1 CRITICAL, 396 HIGH. That corpus is assembled for machine-learning training and deliberately includes known-false-positive categories, so its 8.40% HIGH-or-CRITICAL share is not a false-positive rate over a typical customer file mix. Figures measured on engine source, not on a release binary.

HADES is an enterprise metadata forensics engine built for security teams and incident responders. Measured 2026-09-13 on engine source at commit de6bf83f (v1.7.1 plus unreleased detection changes) across 15,156 malware samples: 99.72% detection on MalwareBazaar (3,269), 99.98% on Contagio (11,877), 100% on the targeted Gootloader set (10 files), and 99.93% overall, with 10 samples undetected and 1 timeout. A separate 4,726-file clean corpus scanned the same day returned 1 CRITICAL and 396 HIGH; that corpus is built for machine-learning training and deliberately includes known-false-positive categories, so its 8.40% HIGH-or-CRITICAL share is not a false-positive rate over a typical customer file mix. Figures measured on engine source, not on a release binary. Multi-layer detection combines 144 YARA detection rules across 55 rule files, ML ensemble models, behavioral analysis, 20 dedicated forensic analyzer modules, and deep format parsing, without executing target files. Two-axis scoring (confidence × severity), with court-ready evidence handling and automated response playbooks.

Get HADES Feed It Something Nasty → View on GitHub

Get Started

HADES v1.7.1 is available now via two install paths. Buy a license at the customer portal or try the live demo in your browser first.

$ # Path A: signed direct download (Linux + scripted installs)
$ export HADES_LICENSE_KEY="..." && curl -fL -H "Authorization: Bearer $HADES_LICENSE_KEY" \
"https://portal.darkhorseinfosec.com/api/v1/download/linux-x86_64/latest/hades" -o hades && chmod +x hades
$ # Path B: Homebrew tap (Linux)
$ export HOMEBREW_HADES_LICENSE_KEY="..." && brew install DarkHorse-InfoSec/tap/hades-scanner
$ # Then:
$ hades scan suspicious_file.jpg # Scan a file
$ hades scan -r /path/to/evidence/ # Recursive directory scan
$ hades-server --port 8666 # Start API server + dashboard
  • No Python runtime needed, the binary is Nuitka-compiled with all dependencies bundled inline. ExifTool is optional for scanning (a native fallback ships in the binary) and recommended for the metadata sanitizer.
  • Linux x86_64 and Windows x86_64 available today; Windows binaries are Authenticode-signed and RFC3161-timestamped. macOS is not yet available and has no release date.
  • License required, Pro+ tier unlocks YARA, ML, deep format analysis; community tier (no license) runs heuristics + IOC only

Capabilities

Metadata Forensics & Deep Format Analysis

Core scanning engine, extracts metadata and runs 20 dedicated forensic analyzer modules. Deep-parses PDF (shadow attacks, filter chains), Office (macros, DDE, VBA stomping, hidden content), RTF (Equation Editor, template injection), archive structures (Zombie ZIP, RAR5/7z), and analyzes audio, video, email, and web file metadata for embedded threats.

Detection Layers:

  • 20 forensic analyzer modules, including PDF, Office/OLE, RTF, OneNote, LNK, MSI, PE, JAR/APK, fonts, firmware, scripts, email, HTML, CSV, EPS, TIFF, steganography
  • Archive forensics: Zombie ZIP, concatenation, bombs, RAR5/7z headers
  • Document forensics: RTF, LNK, legacy Office, OneNote, VBA stomping
  • Audio/video: MP3 ID3, WAV, OGG, FLAC, MKV, MP4, AVI metadata
  • Email/web: phishing detection, CSV formula injection, HTML threats, EPS
  • Steganography: JPEG DCT analysis, palette stego, EOF data, tool signatures
  • 144 YARA detection rules across 55 rule files + firmware analysis (UEFI, SPI flash, BadUSB, wipers)
$ hades scan -r /evidence --format json

ML Ensemble & Behavioral Analysis

Multi-model machine learning ensemble (Isolation Forest + Random Forest + optional XGBoost) with 25 statistical features including Shannon entropy statistics. Behavioral engine detects coordinated attack campaigns through IOC correlation and metadata pattern similarity.

Analysis Capabilities:

  • Weighted multi-model voting with labeled data management
  • Campaign detection via shared IOC correlation (union-find)
  • Metadata similarity scoring (Jaccard) and temporal clustering
  • GPS forensics with impossible travel detection
  • Auto-retraining on labeled datasets with CSV import/export

MITRE ATT&CK Mapping

Automatic mapping of detection findings to 51 MITRE ATT&CK techniques across 14 tactics. Every finding is classified with technique IDs, tactic categories, and severity scores, ready for compliance reporting and threat intelligence correlation.

Coverage:

  • 51 techniques: script injection, backdoors, steganography, polyglot, macros, encoding
  • 14 tactics, from Reconnaissance through Impact
  • 83 finding types mapped to techniques
  • API endpoint for technique lookup and tactic queries

Evidence Chain & Case Management

Forensic-grade evidence handling, SHA-256 hash-chained immutable audit log, case management with analyst notes, and self-verifying evidence export packages with HMAC-SHA256 signatures. Built for court-admissible forensics.

Forensic Features:

  • Append-only hash-chained audit log with tamper detection
  • Case CRUD with scan linking and analyst notes
  • Evidence export as self-verifying ZIP (includes verify script)
  • Chain of custody timeline
$ hades case create "IR-2026-001" $ hades case export CASE_ID

Automated Response Playbooks

Event-driven response automation with 10 built-in playbooks covering phishing triage, malware analysis, BEC detection, ransomware response, and insider threat workflows. Actions include case creation, SIEM forwarding, Slack/Teams notification, evidence export, and file quarantine.

Playbook Engine:

  • Trigger conditions: threat score, YARA match, finding type, file extension, sender domain
  • Priority ordering with retry and exponential backoff
  • Per-action status tracking and execution history
  • Quarantine manager with audit trail
  • WebSocket broadcast for real-time dashboard updates

REST API & Dashboard

FastAPI server with authenticated endpoints, WebSocket live updates, and a 12-view browser-based dashboard.

Interface Options:

  • FastAPI with async endpoints, Pydantic models, Swagger UI at /docs
  • 12-view dashboard: Scan, Monitor, Cases, Audit, System, MITRE, Rules, Analytics, Playbooks, Alerts, Quarantine, Sanitize
  • X-API-Key auth, rate limiting, CORS, WebSocket
$ hades serve --port 8666

Enterprise Security & Observability

Role-based access control with admin/analyst/viewer roles, SSO via OIDC and SAML, AES-256-GCM field-level encryption at rest, multi-tenant isolation, and full observability with Prometheus metrics and four pre-built Grafana dashboards.

Enterprise Features:

  • RBAC with permission matrix and API key rotation
  • SSO: OIDC JWT validation, SAML AuthnRequest, JIT user provisioning
  • AES-256-GCM encrypted storage with key management
  • Multi-tenant isolation with API key to tenant mapping
  • Prometheus metrics (21), Grafana dashboards (4), Alertmanager

SIEM & Platform Integrations

Native SIEM connectors for Splunk HEC, Elasticsearch, and Microsoft Sentinel with batching, retry, and health checks. Format-based output in Syslog, CEF, STIX, LEEF, and ECS. Plus cloud storage scanning (S3, GCS, Azure), network sensors (Zeek, Suricata), email gateway, CI/CD pipelines, and Slack/Teams bots.

Integration Points:

  • Native SIEM: Splunk HEC, Elasticsearch bulk API, Sentinel Log Analytics
  • Cloud: AWS S3, Google Cloud Storage, Azure Blob Storage
  • Network: Zeek connector, Suricata connector, SMTP email gateway
  • DevOps: CI/CD scanning with SARIF output, GitHub/GitLab integration
  • Chat: Slack bot with Block Kit, Teams bot with Adaptive Cards

Deployment & Scaling

Deploy as a single self-contained binary, no Python, ExifTool, or other runtime needed on the host. The binary ships with its full dependency tree bundled inline via Nuitka. Async scan pipeline with persistent in-process worker pool, two-tier scan caching, and pipeline profiler all run inside the binary. Containerized + distributed deployments (Docker Compose, Kubernetes Helm chart with HPA, Redis-backed worker queues) are on the Enterprise roadmap.

Deployment Options:

  • Single-process binary (Linux x86_64 and Windows x86_64 today; macOS not yet available)
  • Direct download via signed URL from the customer portal, or Homebrew tap (DarkHorse-InfoSec/tap)
  • FastAPI REST API server (hades-server) for SOC integrations and CI/CD pipelines
  • Containerized + distributed deployments (Docker Compose, Kubernetes Helm chart, Redis-backed worker queues) on the Enterprise roadmap
$ export HADES_LICENSE_KEY="..." && curl -fL -H "Authorization: Bearer $HADES_LICENSE_KEY" \ https://portal.darkhorseinfosec.com/api/v1/download/linux-x86_64/latest/hades -o hades && chmod +x hades

Pricing

HADES is a proprietary platform with a free Community tier. Paid tiers are unlocked via license key activation.

Community

Free
  • 10 scans/month
  • Heuristic & IOC detection
  • Threat score & severity summary
  • Evidence chain
  • 10 MB file size limit
Try the Demo

Team

$299/mo

$2,499/yr (save 30%)

  • 50,000 scans/month
  • Everything in Professional, plus:
  • RBAC (admin/analyst/viewer roles)
  • SSO (OIDC + SAML)
  • Cloud scanning (S3, GCS, Azure)
  • CI/CD pipeline integration
  • Slack & Teams bots
  • AES-256-GCM encrypted storage
  • 500 MB file size limit
Monthly Annual (save 30%)

Enterprise

Custom

Annual contract

  • Unlimited scans
  • Everything in Team, plus:
  • Multi-tenant isolation
  • Unlimited file size
  • Dedicated support & custom SLA
Contact Sales

Annual plans save up to 33%. Contact sales@darkhorseinfosec.com for volume discounts.


Frequently Asked Questions

Is HADES free to use?
Yes. The Community tier is completely free and includes heuristic & IOC detection, evidence chain, and threat scoring. Professional ($99/mo), Team ($299/mo), and Enterprise (custom annual) tiers add ML ensemble detection, YARA rules, RBAC, SSO, cloud scanning, and multi-tenant isolation. Annual plans save up to 33%.
Does HADES execute the files it scans?
No. HADES performs purely forensic analysis of file metadata and structure. It never executes, opens, or renders target files. This makes it safe to use on suspected malware without risk of detonation.
What are the system requirements?
A 64-bit OS. The HADES binary is Nuitka-compiled with its Python interpreter, YARA engine, and all Python dependencies bundled inline, so the host needs no pre-installed runtime. ExifTool is optional for scanning (a native fallback ships in the binary) and recommended for the metadata sanitizer. Linux x86_64 (glibc 2.34+) and Windows x86_64 are available today via direct portal download; Linux is also on the Homebrew tap. macOS is not yet available and has no release date.
Can HADES run in an air-gapped environment?
Yes. HADES has zero required network dependencies. Cloud threat intelligence, SIEM connectors, and other network features are optional. The core engine, YARA rules, and ML models all run locally.
What file types does HADES support?
HADES analyzes metadata across all major file format families: images (JPEG, PNG, GIF, BMP, TIFF, WebP, HEIF, SVG), documents (PDF, DOCX/XLSX/PPTX, RTF, legacy .doc/.xls/.ppt, OneNote), archives (ZIP, RAR, 7z with deep structural forensics), audio (MP3, WAV, OGG, FLAC, M4A), video (MKV, MP4, AVI, FLV), email (.eml, .msg), web files (HTML, CSV, EPS/PostScript), shortcuts (.lnk), fonts (TTF, OTF, WOFF), installers (MSI), Java/Android (JAR, APK), and firmware (UEFI, SPI flash, BIOS). Each format has a dedicated forensic analyzer with format-specific threat detection.
How does HADES differ from ExifTool alone?
ExifTool extracts metadata, HADES analyzes it for threats. HADES adds YARA-based threat detection, ML ensemble anomaly scoring, deep format analysis (PDF JavaScript, Office macros, polyglot files, Zombie ZIP attacks, VBA stomping, RTF exploits, LNK payloads, audio/video metadata threats, email phishing, CSV formula injection, HTML credential harvesting), behavioral campaign detection, MITRE ATT&CK mapping, court-ready evidence handling, and automated response playbooks on top of ExifTool's extraction capabilities.
What specific threats can HADES detect in file metadata?
HADES detects threat categories including: Zombie ZIP attacks (compression method mismatch), PDF shadow attacks (incremental update abuse), VBA stomping (source/p-code mismatch), RTF Equation Editor exploits (CVE-2017-11882), weaponized LNK shortcuts (PowerShell payloads, icon harvesting), OneNote embedded executables, CSV formula injection (=CMD, DDE), HTML credential harvesting and phishing, steganography (JPEG DCT analysis, palette manipulation), image decompression bombs, timestamp stomping (anti-forensic detection), archive bombs (ZIP, RAR, 7z), and many more. Every finding is mapped to MITRE ATT&CK techniques.
Does HADES integrate with my existing SIEM?
Yes. HADES includes native API connectors for Splunk HEC, Elasticsearch, and Microsoft Sentinel, plus format-based export in Syslog (RFC 5424), CEF (ArcSight), STIX 2.1, LEEF (QRadar), and ECS (Elastic). All connectors support batching, retry with exponential backoff, and health checking.
Case Study: Gootloader ZIP Evasion Detection
Gootloader concatenates hundreds of ZIP archives into a single file (319 to 1,007 end-of-central-directory records per file in the samples we tested) to evade hash-based detection. HADES detects them at CRITICAL, online and air-gapped, by analyzing ZIP structural anomalies: 100+ duplicate local file headers and end-of-central-directory records. Tested against 9 real Gootloader samples from MalwareBazaar, 9/9 detected, zero false negatives. Read the full case study →
Case Study: Curing a Document FP Class (v1.4.4)
A customer reported a 20 KB Microsoft Excel class roster scoring 84 HIGH. We traced four structural defects plus one YARA-filter gap, shipped a layered cure, added a synthetic 100-document business-document regression corpus, and closed a PII-redaction gap discovered along the way. Result: 100/100 synthetic business documents (XLSX, DOCX, PDF, PPTX) scored below HIGH at Pro tier; customer xlsx now 0 SAFE; emails, phones, SSNs, and credit cards redacted at the result-serialization boundary. Read the full case study →
Case Study: Curing a Multi-Revision PDF FP Class (v1.4.5)
A multi-revision PDF whitepaper scored 80 HIGH at Pro tier. We attempted a static dampening predicate, watched G5 corpus replay catch 5 known-malicious MalwareBazaar PDFs regressing to SAFE, then refactored to a threat-intel-gated dampening decision at the engine post-threat-intel layer. Bonus: 3 MalwareBazaar ZIP samples that had regressed to SAFE recovered to HIGH 89-90 via two-layer per-member archive recursion. Result: customer Whitepaper 80 to 22 LOW; 5 known-malicious MalwareBazaar PDFs preserved at HIGH 73 (intel-dispositive); clean corpus actionable FPs cut by 222. The pattern generalizes to any analyzer that wants to dampen on a no-smoking-gun predicate. Read the full case study →

Ready to detect hidden threats in your file metadata?

Get HADES GitHub Book a Demo