Rapidly Investigate Cyber Incidents
Automated Investigation Platform for SOCs, MSSPs, DFIR Teams, and Law EnforcementCyber Triage is automated DFIR software that empowers your team to quickly investigate incidents.
- Scores artifacts so you quickly focus on relevant data.
- Scans executables with 40+ malware detection engines.
- Recommends artifacts so you follow up on all leads.
- Integrates with EDRs for rapid endpoint triage after alerts.
- Deploys in environments agents can’t be used.
INVESTIGATE IN MINUTES
Automation means faster decisions.
- Find
- Evidence ASAP with EDR and SOAR integrated collection.
- Relevant artifacts immediately with automated analysis.
- Every lead fast with artifact recommendation.
Automation means comprehensive investigations.
- Comprehensive
- Collection that covers all relevant artifact + attack scenarios.
- Analysis that scours millions of records for clues.
- Automation that ensures the basics are airtight.
Automation means empowered teams.
- Maximize
- Productivity of understaffed teams with automated analysis.
- Impact of jr. responders with a UI built for all experience levels.
- Teamwork with shared findings and collaborative investigations.
- Flexibility with deployments on laptop, cloud, or on-prem server.
Built by Forensics Veterans
Cyber Triage is built by Sleuth Kit Labs, a spinout of BasisTech. This is the same team responsible for 20+ years of open source tools, including Autopsy and The Sleuth Kit (TSK). Sleuth Kit Labs believes in making the jobs of those on the front lines easier by making software that is automated and easy to use. The company understands that it can’t decrease first responders’ responsibilities, but it can make digital forensics as easy and effective as possible.
Find and Remove Attackers Before They Cause More Damage
Cyber attacks are more frequent and sophisticated so your organization will likely experience an intrusion.That’s why you need a forensics tool that you can count on to help you quickly and accurately determine what is happening.
Cyber Triage is uniquely designed to allow first responders to conduct fast, efficient investigations so that they can understand what happened, get attackers out, and start taking steps to prevent future attacks.
Cyber Triage vs. Endpoint Detection and Response (EDR)
They Work Together
EDRs are optimized for detection. Cyber Triage is optimized for investigations. Integrate them so that you can quickly investigate after the EDR alert.
More Comprehensive
EDRs will not have all data. EDR evasion, throttling, and retention policies mean that you will need additional data for your investigation.
Faster Investigations
EDR focuses on detection with low false positives. Cyber Triage focuses on investigations, which means we show you suspicious data that could be critical clues.
No Agents Required
Cyber Triage leverages your EDR agents for remote endpoint access. Use existing agents to collect and upload data for analysis.
Cyber Triage vs. Ad-Hoc
More Comprehensive
There are many free DFIR tools available and it’s common for organizations to start with a free DIY approach. However, free solutions have limited functionality which don’t give you what you need.
Faster Than Ad-Hoc
Manually consolidating and reviewing the outputs of 12 or 15 command line tools can be very time intensive and error prone. Cyber Triage integrates the data into a single interface and uses scoring to make sure you can quickly focus on what is relevant.
Integrates With Enterprise Systems
Cyber Triage’s API integrates with enterprise orchestration systems to collect data and deploy.
Makes Malware Scanning Accessible
DFIR teams require usage bursts for threat intelligence data, such as scanning for malware. It is cost prohibitive for many organizations to purchase a malware scanning service that gives them access to the engines they need. Cyber Triage includes API access to 40+ engines at limits that a typical examiner would use.
Cyber Triage vs. General Purpose Forensics Tools
Optimized for intrusions
Cyber Triage is built from the ground up to optimize specifically for intrusions. General purpose forensics tools lack the depth of functionality and workflows needed to identify and block intruders.
Faster interface
General purpose tools require the user to know which artifacts they should look at and which they should ignore. Cyber Triage only focuses on artifacts relevant to intrusions, which makes the user interface more simple and faster.
Identifies Starting Point
General purpose tools require the user to review each artifact and determine if they are relevant. Cyber Triage scores each artifact based on relevance so the user can quickly focus on where to start the investigation.