# Cyber Triage: Digital Forensics Specialized For Rapid Incident Response > Cyber Triage is automated Digital Forensics and Incident Response \(DFIR\) software that allows cybersecurity professionals like you to quickly answer intrusion questions related to malware, ransomware, and account takeover\. Generated by Yoast SEO v28.1, this is an llms.txt file, meant for consumption by LLMs. ## Pages - [Home \(June 2026 5 New Final\)](https://www.cybertriage.com/) - [Digital Forensics Data Collection](https://www.cybertriage.com/features/digital-forensics-data-collection/) - [Home \(April 2026\)](https://www.cybertriage.com/) - [Home \(March 2026 \- Rollback of August 2025\)](https://www.cybertriage.com/) - [SOC Investigations with Cyber Triage](https://www.cybertriage.com/soc-alert-investigation/) ## Posts - [DFIR\+AI: Making Tool Decisions in a GenAI World](https://www.cybertriage.com/blog/dfirai-making-tool-decisions-in-a-genai-world/) - [How to Use EDR Telemetry in DFIR: 3 Investigation Methods Compared](https://www.cybertriage.com/blog/how-to-use-edr-telemetry-in-dfir-3-investigation-methods-compared/) - [SANS vs SKL DFIR AI Frameworks: When to Use Each](https://www.cybertriage.com/ai/sans-vs-skl-which-ai-framework-should-you-use/) - [DFIR\+AI 2026 Challenge Winners](https://www.cybertriage.com/blog/dfir_ai-2026-challenge-winners/) - [3 AI Prompts for More Confident DFIR Investigations](https://www.cybertriage.com/blog/3-ai-prompts-for-more-confident-dfir-investigations/) ## Integrations - [Swimlane](https://www.cybertriage.com/integration/swimlane/) - [SentinelOne Singularity](https://www.cybertriage.com/integration/sentinelone-singularity/) - [Windows Defender for Endpoint](https://www.cybertriage.com/integration/windows-defender-for-endpoint/) - [Claude Desktop/Code](https://www.cybertriage.com/integration/claude-desktop-code/) - [CrowdStrike Falcon](https://www.cybertriage.com/integration/crowdstrike-falcon/) ## Contributors - [Mike Wilkinson](https://www.cybertriage.com/team/mike-wilkinson/) - [Larissa Duzhansky](https://www.cybertriage.com/team/larissa-duzhansky/) - [Alex Detmering](https://www.cybertriage.com/team/alex-detmering/) - [Chris Ray](https://www.cybertriage.com/team/chris-ray/) - [Dr\. Brian Carrier](https://www.cybertriage.com/contributor/dr-brian-carrier/) ## Videos - [Cyber Triage 3\.13 Release Webinar](https://www.cybertriage.com/video/cyber-triage-3-13-release-webinar/) - [Cyber Triage 3\.12 Release Webinar](https://www.cybertriage.com/video/cyber-triage-3-12-release-webinar/) - [Demo Data Set Overview](https://www.cybertriage.com/video/demo-data-set-overview/) - [Cyber Triage Lite – USB to Network Collections Video](https://www.cybertriage.com/video/cyber-triage-lite-usb-to-network-collections-video/): This video shows you how to collect data from a live\-running host and import it into Cyber Triage Lite over the network\. The collection tool in this case is launched from a network drive or USB share\. - [How to Respond with Cyber Triage](https://www.cybertriage.com/video/how-to-respond-with-cyber-triage/) ## Versions - [Standard Pro](https://www.cybertriage.com/version/standard-pro/) - [Team](https://www.cybertriage.com/version/team/) - [Standard](https://www.cybertriage.com/version/standard/) - [Lite](https://www.cybertriage.com/version/lite/) ## Artifacts - [Local Session Manager \- Event 24 \(Disconnect\)](https://www.cybertriage.com/artifact/terminalservices_localsessionmanager_log/terminalservices_localsessionmanager_operational_24/) - [Windows Terminal Server \- Remote Connection Manager Log](https://www.cybertriage.com/artifact/terminalservices_remoteconnectionmanager_log/) - [Remote Connection Manager \- Event 261](https://www.cybertriage.com/artifact/terminalservices_remoteconnectionmanager_log/terminalservices_remoteconnectionmanager_operational_261/) - [Local Session Manager \- Event 21 \(Logon\)](https://www.cybertriage.com/artifact/terminalservices_localsessionmanager_log/terminalservices_localsessionmanager_operational_21/) - [Windows Terminal Services \- Local Session Manager Log](https://www.cybertriage.com/artifact/terminalservices_localsessionmanager_log/) ## Glossary Terms - [Digital Forensics \& Incident Response](https://www.cybertriage.com/glossary-term/digital-forensics-incident-response/): Was a computer used in a crime? Did someone break into it? Did it malfunction or fail? The process of Digital Forensics \& Incident Response or DFIR emerged when computer scientists needed to understand what happened with the machine in the past\. Digital forensics involves analyzing the data stored inside the computer and Incident Response is the strategy of the best way to handle any breach that’s been detected\. Together the processes formalized the best possible approaches to answering the questions of how and when someone accessed the data inside a computer\. - [Timeline Analysis for Incident Response](https://www.cybertriage.com/glossary-term/timeline-analysis-for-incident-response/): When a forensics team is called to investigate, one of the most important techniques they can deploy is to create a timeline of the events\. The breach is often the result of several different failures or weaknesses and the timeline allows investigators to gather all of the evidence in a single chart\. Collecting all of the details in one coherent data structure can improve analysis\. While some breaches have obvious causes, some can only be understood after all of the failures can be analyzed together\. Timelines make it easier to understand causality and the relationships between the many moving parts of a modern enterprise stack\. - [What Are YARA Rules?](https://www.cybertriage.com/glossary-term/what-are-yara-rules/) - [What is Behavioral Analysis and Signature Analysis?](https://www.cybertriage.com/glossary-term/what-is-behavioral-analysis-and-signature-analysis/): Forensic investigators look for patterns and this investigation often takes two forms that complement each other\. The first is a very focused and efficient search for the unique sequences of bytes found inside known malware\. Finding these attack signatures is fast and effective\. The second part is more general\. The patterns of events like API calls, or database queries offer a historical record of what happened in the computer\. Deconstructing this data can reveal how and when malicious behavior began and an attacker gained access\. This analysis is more complex and time consuming, but it can be more effective at detecting new or unknown attacks\. Deployed together, the approaches can speed detection, evidence collection and analysis\. - [Types of Security Incidents](https://www.cybertriage.com/glossary-term/types-of-security-incidents/): Digital forensic teams are called to investigate a wide range of incidents that range from active security breaches committed by aggressive outsider attackers to passive, unintentional leaks brought about by mistakes and misconfiguration\. ## Categories - [Blog](https://www.cybertriage.com/topics/blog/) - [New Features](https://www.cybertriage.com/topics/blog/new-features/) - [Training](https://www.cybertriage.com/topics/blog/training/) - [Releases](https://www.cybertriage.com/topics/blog/releases/) - [Editorial](https://www.cybertriage.com/topics/editorial/) ## Tags - [incident response](https://www.cybertriage.com/tag/incident-response/) - [cyber triage](https://www.cybertriage.com/tag/cyber-triage/) - [automated incident response](https://www.cybertriage.com/tag/automated-incident-response/) - [endpoint investigation](https://www.cybertriage.com/tag/endpoint-investigation/) - [OODA Loop](https://www.cybertriage.com/tag/ooda-loop/) ## Glossary Types - [DFIR](https://www.cybertriage.com/glossary_type/dfir/) ## Optional - [Sitemap index](https://www.cybertriage.com/sitemap_index.xml)