๐ Read-only by design. The process never writes to the suspect disk.
Bonzentu Trace
Got hacked? Find out what happened โ yourself.
A step-by-step field guide and script pack for examining a compromised Windows PC from a USB stick โ without turning Windows on โ with your own AI assistant doing the heavy reading.
- Read-only by design
- Built on a real 14-month case
- Delivery by 15 November 2026, or your money back
- Full refund any time before delivery
Built for one job: finding out what happened.
๐งช Built on a real case. Developed and proven on one real 14-month intrusion. Redacted sample report included.
๐งญ Ends with a plan. What was installed, when, what may have been taken, and what to change next.
1Find the suspect diskPanel: Identify DisksRead-only. Shows every disk and marks the suspect disk by serial.
2See which programs ranPanel: Prefetch ParseRead-only. What programs ran in a time window you choose.
3Search for known attacker tracesPanel: IOC SweepRead-only. Looks for the known attacker names, addresses and files.
4Seal a small copy of the key evidencePanel: Sealed Triage TarRead-only on the evidence. Small sealed copy of the key evidence files.
5Copy the whole diskPanel: Image DiskMakes the full E01 copy. Asks you to type IMAGE before it writes.
6Check the copy matchesPanel: Verify ImageRe-reads the finished copy and checks it matches. Run after Image Disk.
The software
Six steps. One window.
The Trace Panel: one click per investigation step. Do them in order, top to bottom. Nothing runs until you press OK.
ORDER-1 collectORDER-2 analyseORDER-3 reportGive the three orders to Claude Code one at a time. Early Access v0.8; details may change before v1.0.
Is Trace right for you?
Who it's for
- people and very small businesses who think a Windows PC was taken over.
- What you need: the Windows PC, a second computer to make the sticks, two USB sticks (sizes in the guide), and your own Claude plan with Claude Code (sold separately by Anthropic). Optional: an external drive larger than the suspect disk, for a full disk image (Image Disk).
Who it's NOT for
- โ๏ธ If you need evidence for police, court or insurance, stop. Report at ic3.gov or to local police, and leave the PC untouched.
- ๐ธ This is not a recovery service. Nobody can promise to get stolen money back. The FBI warns that "fund recovery" companies are often scams.
Early Access
$29 Presale โ Early Access
- $29 today. Becomes $49 at v1.0; presale buyers upgrade free.
- Download by email by 15 November 2026.
- Goes ahead at 73 buyers by 8 November 2026.
- Refunds: full refund any time before delivery, and automatically if it isn't delivered by 15 November 2026 or if fewer than 73 people buy by 8 November 2026. After delivery, 14 days for any reason.
Bonzentu Trace is built by Aaron D. Harris and sold by BONZENTECH, LLC (Oklahoma). Not affiliated with Anthropic or the CAINE project. Terms ยท Privacy ยท Refunds ยท Contact.
Questions, answered.
What do I get?
The current Early Access version of the Trace Field Guide, script pack, order templates and redacted sample report, as a download.
What's not included?
The CAINE operating system (download it free from its official site), Claude Code or any Claude plan (sold by Anthropic), and USB drives.
Does it change anything on the PC?
Read-only by design. The process never writes to the suspect disk. Image Disk writes only to a drive you choose, and asks you to type IMAGE before it writes.
When does the presale arrive?
Your download arrives by email by 15 November 2026, if at least 73 people have bought by 8 November 2026.
What if I want a refund?
Full refund any time before delivery: email [email protected]. It's automatic if Trace isn't delivered by 15 November 2026 or if fewer than 73 people buy by 8 November 2026. After delivery, you have 14 days to ask for a refund, for any reason.
Can you get my money back?
This is not a recovery service. Nobody can promise to get stolen money back. The FBI warns that "fund recovery" companies are often scams.
Do you see my files?
No. The Trace Field Guide runs on your own computers. We never receive your files, evidence, findings or reports.