3 Ways to Make Digital Investigations Faster with Automation
Everyone β except for some consultants paid by the hour β wants to skip the tedious work associated with digital investigation. The good news is there are
Adding automation to your #DFIR investigations means you have less decisions to make. Get rid of the tedious work! Focus on the fun stuff!
Here are my three thoughts on the most effective ways to add automation and which tools do them.
What are yours?
www.cybertriage.com/blog/3-ways-...
05.08.2025 15:29 β π 4 π 3 π¬ 0 π 0
New Cyber Triage release with:
* New UIs to give you an overview of the endpoint
* Hyabusa integration
* Baseline
* Public key encryption on collector
* LOTS more....
Blog and Download Link: www.cybertriage.com/blog/3-14-re...
06.05.2025 14:39 β π 5 π 4 π¬ 0 π 0
EDRs miss activity! π²π±.
You should not miss webinar tmrw! π
Markus and I will talk about why EDR alerts could be days after an attack started.
We'll talk about how to do endpoint triage to see what else happened beyond the alert!
Mar 27 @ 11 Eastern
register.gotowebinar.com/register/916...
26.03.2025 14:55 β π 3 π 3 π¬ 0 π 0
Alert Triage vs Endpoint Triage: What SOCs Need to Know
As we talk to corporate security teams about how they respond to incidents and EDR alerts, we find it useful to highlight the Endpoint Triage step in
For those in the #SOC: Alert Triage vs Endpoint Triage
Blog post that is part of our Endpoint Triage series.
Alert triage focuses on validating and prioritizing the EDR/SIEM alert.
Endpoint triage focuses on prioritizing the host. How bad is it?
www.cybertriage.com/blog/alert-t...
21.03.2025 13:38 β π 4 π 4 π¬ 0 π 0
I'm doing a webinar TMRW on investigation tools for endpoint triage. Basic idea is how to get quick and accurate results after an alert. EDR data plays a role in that, but it's not enough.
Endpoint Triage should be in any security team's process.
attendee.gotowebinar.com/register/281...
25.02.2025 15:30 β π 3 π 1 π¬ 1 π 0
3 places to automate #DFIR Endpoint Triage. Which do you do?
11.02.2025 16:00 β π 1 π 1 π¬ 1 π 0
The 3 themes we focus on for #DFIR endpoint triage. What are yours?
04.02.2025 21:47 β π 2 π 1 π¬ 0 π 0
03.02.2025 18:48 β π 2 π 1 π¬ 1 π 0
31.01.2025 14:23 β π 4 π 2 π¬ 0 π 0
Endpoint Triage: What you do after you validate the EDR alert to understand the impact.
#DFIR Webinar Thu @ 11.
register.gotowebinar.com/register/142...
28.01.2025 16:14 β π 3 π 1 π¬ 0 π 0
3.13 Adds MemProcFS and Extends the S3 and Recorded Future Sandbox Integrations
Our holiday gift this year is some frequently requested features that came out in the 3.13 release: MemProcFS to support Windows 10 and 11 images
Cyber Triage 3.13 is the holiday gift youβve been waiting for:
Integrations that make you faster.
β MemProcFS integration
β Expanded S3 integration
β Detailed sandbox report
Complete 3.13 release notes: www.cybertriage.com/blog/release...
19.12.2024 22:56 β π 10 π 4 π¬ 1 π 0
DFIR by day, DFIR by night.
Former vet tech.
Violinist, Salty, Tired, Meme Enthusiast.
Mobile Forensics Researcher. iOS nerd. ο£Ώ fanboy. Opinions are my own, not my employer.
Sleuth Kit Labs is the maker of The Sleuth Kit, Autopsy, and Cyber Triage digital forensics tools.
π€ Digital forensics nerd.
πΉ Mobile forensics is my passion.
π‘ Opinions are mine and subject to change.
ποΈ Co-host of The Digital Forensics Now Podcast
π€ He/Him
π linqapp.com/abrignoni
DFIR and Adversary Simulation | DFIR @ ProtonMail
Leading digital forensics and DFIR news, analysis and discussion. Join us at www.forensicfocus.com
Lethal forensicator, researcher, developer, blogger, curator of many fine t-shirt designs, resident #DFIR beer drinker
https://startme.stark4n6.com
https://thebinaryhick.blog
Digital Forensics and Public Defense for The Legal Aid Society. Posts are my own, not my employer's. @JeromeDGreco on Twitter.
https://digitalforensicslas.substack.com/
A #DFIR, #infosec, #dadjokes, #scifi, #books, #rpg, #ttx, #malware, elder #genx, and #gaming nerd. AKA an elder geek. Retired #leo. Current #infosec in #OT.
Kindness first is useful but telling off toxic folks is on my response spectrum too.
Fell off a cliff. Swam with sharks. Dined with hitmen. Hung out with crime bosses. Bought and sold a ton of drugs. How the heck am I still here? DFIR USMC π
@volatilityfoundation.org Core Dev | Art of Memory Forensics co-author | DFIR trainer and enthusiast | Director of Adversary Tactics @huntress.com
@mttaggart@infosec.exchange. Displaced Philly boy. Threat hunter. Educator. Dad.
taggartinstitute.org
wtfbins.wtf
linktr.ee/mttaggart
Advances cybersecurity. Grows tech businesses. Fights malware.
CISO at Axonius. Faculty Fellow at SANS Institute. Creator of REMnux.
https://zeltser.com
OSINT, InfoSec, learning new things, writing, good movies, movies so-bad-they're-good, love a good laugh. I try to do good. I have more questions than answers.
DFIR, LEGO, Manchester United, Marvel, Technology, xLights
Digital Forensic Investigator, Incident Responder, HAM, ambassador for flip-flops and purveyor of fine Dad Jokes. #DFIRFit