DON’T MISS DFIR EVIDENCE

Automated Ingest pulls in every source of investigation data.

Table of Cyber Triage Automated Ingest capabilities: DFIR collection is supported through Cyber Triage's Adaptive Collector, KAPE, and other collectors. Remote collection, automated collection, disk image import, memory image import, and EDR telemetry import are all supported. Average collection speed is 20 to 30 minutes. SIEM log import and cloud log import are coming soon.

Your DFIR evidence engine.

Automated Ingest imports data from any relevant source and launches its own DFIR collections with one click.

Start every investigation with every lead.

ACCESS ALL YOUR DATA

Cyber Triage connects to your tech stack and pulls in all relevant data for analysis. This includes other collectors like KAPE, EDRs like Defender, and disk imagers like FTK.

The result: Your conclusions are based on all the evidence.

Details

Table of tools and platforms Cyber Triage imports data from: DFIR collection from [Cyber Triage's Adaptive Collector], KAPE, and UAC. EDR telemetry from Microsoft Defender, SentinelOne, and CrowdStrike (coming soon). Disk images from Exterro FTK, Belkasoft, and EnCase.

Use slider to view the artifacts we collect

 

EASILY COLLECT DFIR ARTIFACTS

Cyber Triage has a native, Adaptive Collector that can be launched directly from the Cyber Triage console, an EDR, or as part of an automated SOAR playbook.

The result: You can quickly get DFIR-grade evidence from any endpoint.

Details

AUTOMATED INGEST CAPABILITIES

Cyber Triage imports what you have and collects what you need.

DFIR COLLECTION + IMPORT

Cyber Triage has its own Adaptive Collector and can import data from other DFIR collectors, including KAPE and Velociraptor.

REMOTE COLLECTION

Cyber Triage’s Adaptive Collector can execute remote DFIR collections and can be deployed via the console, EDR, PsExec, PowerShell, MS Intune, and more.

FAST COLLECTION

Cyber Triage can execute comprehensive DFIR collections in an average of 20 - 30 minutes, much faster than traditional DFIR platforms like Magnet AXIOM.

DISK IMAGE IMPORT

Cyber Triage can import disk images from Exterro FTK, Belkasoft Triage, and EnCase Imager.

MEMORY IMAGE IMPORT

Cyber Triage can import memory images and process them using Volatility v2 or MemProcFS.

EDR TELEMETRY IMPORT

Cyber Triage can directly import data from Microsoft Defender, SentinelOne, and (coming soon) CrowdStrike.

CLOUD LOG IMPORT

Cyber Triage will soon import logs directly from cloud platforms like Microsoft 365, Azure, and AWS.

SIEM LOG IMPORT

Cyber Triage will soon import data directly from SIEMs like Splunk and IBM QRadar.

THE IMPACT OF AUTOMATED INGEST

Investigations at a major industrial manufacturer were taking too long. Part of the problem: They couldn’t collect the evidence they needed fast enough.

Then they found Cyber Triage.

“I have used CyberTriage in live incidents and the speed and what it does has been great! Extremely pleased with this software,” said the company’s forensics lead.

Read Case Study

Customer quote from a forensics lead at an industrial manufacturer: “[There are] so many different ways to perform collections with the tool and/or bring existing collections into the software.”

WHAT USERS ARE SAYING

Community testimonial about Cyber Triage
Community testimonial about Cyber Triage
Community testimonial about Cyber Triage
Community testimonial about Cyber Triage

TEST OUR PROMISE

See how Automated Ingest accelerates your investigations with a free with a free, 1-week evaluation.

Start Free Trial

*SIEM and cloud log import coming soon.