Resurge
Resurge ريسيرج
دائما متجدد Always Resurged

Ransomware doesn't wait for a human to notice. Neither does Resurge.

Resurge watches every protected file in real time, isolates the process behind a drift the instant it starts, and restores exactly what it touched — while keeping every high-risk action locked behind your explicit approval, never a silent judgment call.

Download for macOS v0.1.0 · free during early access

Detection and recovery, not just an alert

Most tools tell you something went wrong. Resurge isolates the cause, verifies your backup is actually clean, and restores — before an incident report is even the first thing you see.

Rolling trusted state, not a static snapshot

SHA-256 differential hashing tracks drift against a continuously updated baseline — not a one-time-trained model that goes stale the day it's built.

Isolate, confirm, scan, restore — in that order

The malicious process is confirmed dead and the backup candidate is scanned for dormant malware before a single file is restored, never the reverse.

Tamper-evident by construction

Every action is hash-chained, signed, and anchored to a separate service an attacker's database access can't reach — so blinding the SOC first doesn't work.

Four layers, in order of when they see the attacker

Each layer runs independently. Together they cover the moment someone logs in, the plain read no file-watcher can see, and the encryption itself.

01

Risk-based contextual token

Every login is scored on device fingerprint, IP reputation, and timing — including Haversine-based impossible-travel detection, so a credential used from two continents in ten minutes is caught before it's trusted.

Auth-time · zero footprint on the endpoint
02

Behavioral biometrics

Keystroke and interaction dynamics build a profile of how your team actually works — so a valid session behaving like someone else raises its risk score, not just its login.

Continuous, passive
03

Canary files

Realistic decoy files, watched by three independent channels at once — including Windows Security-audit event tracking, the only one of the three that catches a plain read that never creates, deletes, or renames anything.

Live-tested against real Windows targets
04

Core detection & recovery

The baseline every deployment runs: entropy and hash-based drift detection, isolate-confirm-scan-restore, and a circuit breaker that halts and escalates the moment a burst of changes exceeds a threshold you set.

Always on · foundation for every pilot

Automation you can see the edges of

Resurge acts fast on what's reversible, and stops cold at what isn't. Nothing — including its own reasoning layer — can downgrade a high-risk action to something it can approve itself.

Medium risk

Automatic, then notified

Blocking a live connection, killing a persistence mechanism, suspending a process — executed immediately, reversible, visible in the audit log the instant it happens.

High risk

Locked until you approve it

Revoking credentials or rotating a secret waits for an explicit human decision. Nothing about the action changes while it waits — not even the file it targets.

No response

Escalated, never improvised

An unapproved high-risk action that times out is rejected and logged. It never falls back to a different automated action — a timeout is not a quieter form of approval.

Trust. Control. Resilience. — the boundary between what Resurge does on its own and what it asks you first is never ambiguous, in the interface or in the code.

Choose your platform

Version 0.1.0 · free during early access

macOS
Apple Silicon & Intel · 11.0+
Download for macOS
SHA-256 23feea911d5af26c4e58139a40f06fbfa8e770692ff9c2289a4d911d52e6e763
Windows
Windows 10 & 11
Download for Windows
SHA-256 6d04ea3da2240f95f59ce6e0c469e8d20f1991dbb8ca36d28d1743d2748575fa
Ubuntu
Ubuntu 22.04+ · AppImage
Download for Ubuntu
SHA-256 816d8cd721ce68efb7f3044d9847342381e812a341dd5c58e6d1fe5cf3e7a703