Troy

Laptop software audit

One scan lists every program installed on a laptop, works out which ones need a paid licence, finds cracked or tampered software, checks what is listening on the network, and lets you uninstall from the same window.

What a result looks like

Critical Piracy / tampering 95% confidence

Licence server blocked in hosts file: activate.adobe.com

The hosts file redirects Adobe's activation server to 127.0.0.1. This is the standard way a cracked install stops the software phoning home.

/etc/hosts line 14:  127.0.0.1  activate.adobe.com

→ Remove the line from the hosts file, then confirm Adobe is genuinely licensed.

Every finding carries the evidence that produced it, so nobody has to take the result on trust.

What it checks

Everything installed

Windows registry, MSI and Store packages. macOS application bundles, Mac App Store receipts and Homebrew. Version, publisher, install date and size for each.

Licence status

Windows and Office activation is read straight from the system, so that answer is definitive. Other paid software is flagged for review rather than accused — no vendor reports its licence state to the operating system.

Cracks, keygens and activators

KMS emulators, Adobe patchers, JetBrains licence agents, blackholed activation servers, and binaries whose signed bytes were modified after signing.

Open ports and rogue services

Every listening socket traced back to a process, an executable and a code signature. Flags miners, tunnels, remote-access tools and unsigned programs accepting connections.

Known vulnerabilities

Installed versions matched against the public CVE database and end-of-life dates. Optional — switch it off for a fully offline scan.

First run

macOS

  1. Open the .dmg and drag Troy into Applications.

  2. Right-click Troy and choose Open, then Open again. Double-clicking will be refused the first time — the build is not signed with an Apple developer certificate yet.

  3. Press Run the scan. It takes about half a minute. macOS asks for an administrator password only if you uninstall something.

Windows

  1. Run the installer and accept the administrator prompt. Reading activation state and running uninstallers both need it.

  2. Launch Troy and press Run the scan.

Nothing is changed or removed without you confirming it first. Every uninstall shows the exact command before it runs, and system, driver and security components are blocked outright.

Privacy

Troy reads local system state. That is all.

There are exactly two outbound requests it can make, and both are optional: looking up CVEs for installed versions, and uploading a report when you press the button. No telemetry, no analytics, no background reporting. Export to HTML, CSV or JSON and the file stays on the laptop until you send it somewhere.