Rapidly Investigate Cyber Incidents

AI-powered investigation platform for SOCs, LE, MSSPs, and IR teams from the makers of Autopsy

What Is Cyber Triage?

Cyber Triage is an AI-powered investigation platform. It makes your investigations fast and comprehensive with 3 key features:

INGEST

Access evidence from multiple sources for a comprehensive investigation.

  • DFIR collectors
  • EDR telemetry
  • Disk images

SCORE

Focus on the most relevant data first to immediately get your investigation started.

  • 40+ malware engines
  • YARA / Hayabusa
  • Hybrid AI

RECOMMEND

Get recommendations about what other data to review so you find everything.

  • Other occurrences
  • Related items
  • Timeline
Trusted by

Investigating with Cyber Triage

Where Cyber Triage fits in your incident response process.

START INVESTIGATION

An EDR alert, client call, or incident declaration triggered an endpoint investigation. Now an analyst or investigator needs to figure out what happened.

INGEST DATA

Data is automatically imported into Cyber Triage for analysis from a SOAR, EDR telemetry, and directly from endpoints via The Collector.

This includes forensic evidence EDRs miss.

REVIEW TRIAGE RESULTS

Artifacts are scored as bad, suspicious, good, or unknown and displayed for the investigator to review. They can quickly determine what’s important, where to start, and the scope of the incident.

Artifacts are scored using more detections than any other DFIR tool.

FIND ROOT CAUSE

When necessary, investigators can find root cause using recommendations, timeline analysis, sandbox analysis, and more.

This means you chase down every lead so your investigations are comprehensive.

PUBLISH RESULTS

Send findings to case management, SIEMs, and leadership. Outputs integrate with the tools your team already uses.

The Benefits of Cyber Triage

INVESTIGATE 2X FASTER

Know where to start and what’s important within minutes.


Read the case study: how an IR consultancy cut analysis time ~75% with Cyber Triage

RESPOND WITH CONFIDENCE

Trust your conclusions are based on comprehensive data and analysis.


Read the case study: how a major bank escalated incidents with confidence using Cyber Triage

SCALE WITHOUT COMPROMISE

Optimize your team’s output with shared findings and collaborative investigations.


Read the case study: how a Fortune 150 scaled to 10+ investigators with Cyber Triage

Who Uses Cyber Triage?

IR Teams

Internal IR teams who need to rapidly investigate incidents, determine root cause, and report to management.

SOC Analysts

SOC teams who need to confidently review valid alerts and determine which should be escalated to IR.

Consultants

IR consultants who need to quickly understand what's normal and where to start during a client investigation.

Law Enforcement

Law enforcement teams who need to close intrusion investigations quickly and confidently.

FROM THE CREATORS OF AUTOPSY

Cyber Triage is built by Sleuth Kit Labs, creators of Autopsy and The Sleuth Kit. These widely used open-source tools form the foundation of forensic training programs, law enforcement workflows, and commercial platforms around the world.

Cyber Triage is what this team built by focusing their decades of experience on 1 thing: making DFIR fast, comprehensive, and scalable.

Community Backed

1M+

30K+

130K+

Software downloads since 2023.

DFIR conference registrants.

DFIR course registrants.

FROM THE FIELD

Community testimonial about Cyber Triage
Community testimonial about Cyber Triage
Community testimonial about Cyber Triage
Community testimonial about Cyber Triage
Community testimonial about Cyber Triage

TEST OUR PROMISE

See what Cyber Triage can do for your team with a free, 1-week evaluation.

Try it Now