The Problem
- Insider Threats: Organizations face significant risks from insiders misusing authorized access, leading to financial losses, reputational damage, and legal implications.
- Malware and PUPs: Potentially unwanted programs (PUPs) and malware can infiltrate systems, bypassing traditional security measures.
- Lack of Proactive Detection: Many organizations lack a comprehensive strategy to identify and mitigate insider threats or detect malicious software effectively.
Key Tools of Gargoyle Suite
A Comprehensive Set of Tools for Advanced Threat Detection and Insider Threat Management
The Gargoyle Suite is a collection of specialized tools designed to detect insider threats, identify malicious software, and uncover potentially unwanted programs (PUPs). Powered by an extensive dataset covering over 25 threat categories, Gargoyle Suite offers precise threat classification, rapid detection, and actionable intelligence to secure your digital environment.

Gargoyle Enterprise Manager™ (GEM)
An enterprise-scale solution for proactive detection of insider threats and malicious software.
Key Features:
- Scans network endpoints for PUPs and malware.
- Tailored to organizational security needs with custom search criteria, whitelists, and YARA rules.
- Provides detailed reports with actionable intelligence.
- Regularly updates threat intelligence datasets to stay ahead of emerging risks.
Key Uses:
- Insider threat management
- Malware detection
- Compliance monitoring

Gargoyle Investigator™ MP
A next-generation malware discovery tool for forensic labs, law enforcement, and incident response teams.
Key Features:
- Rapid scans for malicious software and contraband files.
- Advanced detection for over 25 categories, including ransomware, botnets, spyware, and cryptojacking tools.
- Comprehensive reporting for breach investigations and triage.
- Integration with forensic platforms like EnCase® Forensic and Forensic Explorer.
Compatibility:
- Windows desktop (7–10)
- Server platforms (2008–2019)
Use Cases
1. Insider Threat Management
A large organization uses Gargoyle Enterprise Manager to monitor network endpoints for unauthorized tools, such as P2P file-sharing software. By detecting and mitigating insider threats, the organization protects sensitive data and ensures compliance with industry regulations.
2. Forensic Investigations
Law enforcement agencies rely on Gargoyle Investigator MP to uncover contraband and malicious software. Its rapid scanning capabilities and integration with forensic tools simplify investigations and provide admissible evidence.
3. Field Incident Response
Incident response teams use G-FLASH for on-site investigations, enabling rapid detection of malware and insider threats. Its portability and ease of use make it an essential tool for field operations.
File Types Supported
- Images: JPEG, BMP, PNG, TIFF, GIF
- Videos: MP4, MOV, AVI, FLV
- Audio: WAV, MP3
- Documents: PDFs, Office files (.doc, .xls, .ppt), OLE files
- Archives: ZIP, TAR, 7z
Licensing Options
Electronic Software Download (ESD):
- Ideal for single-system use.
- Subscription-based licensing with 2-core support (expandable).

