Stairwell Documentation Center

Comprehensive references documenting how Stairwell works.

Stairwell collects the executables and scripts running across your fleet, keeps them, and lets you ask questions of that history: what is this file, where else is it, what does it resemble, and was it here before anyone told us to look for it.

These docs cover all of it, from the first forwarder to the API. Every page assumes you have not used a tool like this before, and links to the concept it depends on rather than assuming you have met it.

If you are working an alert right now, go to Playbooks and find the situation that matches yours.