stars 1 stars 2 stars 3

Puck is a posture and investigation layer for IR and detection engineering teams. One Rust binary on every endpoint - macOS, Linux, Windows. Read-only by design: no kernel driver, no write paths, no fleet-write capability anywhere in the architecture. Install Friday. By Monday, most teams have surfaced plaintext credentials, long-lived AWS keys, OAuth tokens cached in dotfiles, forgotten admin paths - already in the environment, never previously visible. Three modes, one product. Continuous understanding. Puck holds a live model of every host: credentials, processes, configs, what changed since yesterday. Most IR questions are answered without waking an LLM. Calibrated detection. Patterns Puck has confirmed enough times across your fleet compile into deterministic checks tuned to your environment. Not a vendor's detection pack - the patterns your fleet actually produced. Investigations. Ask in natural language, or pipe in a signal (CVE drop, leaked token, threat-intel tip). Puck plans, agents execute, structured findings return.

Website https://puck.security
Employees 1 (0 on RocketReach)
Founded 2026
Industry Information Services

puck.security Questions

G2 Leader Summer 2026 G2 Best Est ROI Mid-Market Summer 2026 G2 Easiest Admin Mid-Market Summer 2026 G2 Most Implementable Summer 2026 G2 Best Results Mid-Market Summer 2026 G2 Lead Capture Mid-Market Summer 2026 Inc Fastest Growing Private Companies 2026 Inc Best Workplace 2026
g2crowd
G2Crowd Trusted
chromestore
300K+ Plugin Users