Cyber Triage

726 posts

Cyber Triage banner
Cyber Triage

Cyber Triage

@cybertriage

Digital Forensics and incident response software for endpoint investigations. Built by @sleuthkitlabs and Brian Carrier (@carrier4n6).

Cambridge, MA. Katılım Aralık 2014
390 Takip Edilen4.2K Takipçiler
Cyber Triage
Cyber Triage@cybertriage·
DFIR is changing fast. How do investigators adapt their approach to stay effective? Today, 11 AM EST, Blake Regan and Brian Carrier debate when and when *not* to use EDR in DFIR, plus provide tools + techniques to use in modern investigations. Register: register.gotowebinar.com/register/90391…
Cyber Triage tweet media
English
0
0
6
1.1K
Cyber Triage
Cyber Triage@cybertriage·
To EDR or not EDR? That’s the investigator’s question. Next Thursday, Blake Regan and Brian Carrier will tackle that and other questions facing SOC and IR teams trying to adapt to emerging threats and evolving tech. Register here: register.gotowebinar.com/register/90391…
Cyber Triage tweet media
English
0
1
3
419
Cyber Triage
Cyber Triage@cybertriage·
New DFIR Research: Pulseway (RMM) Abuse ⤵ Our team recently observed a threat actor using Pulseway for remote access and gaining full control of a system. Read @MikeWilko's research + investigation tips from the case: cybertriage.com/blog/dfir-next…
English
0
3
4
500
Cyber Triage
Cyber Triage@cybertriage·
85% of attacks use LOTL The Socrates of SOC investigations teaches his best approach⤵ This Thursday, Wade Wells, detection and response expert, shares: → War stories → Investigation approach → Top 3 tips for elite endpoint triage Register: register.gotowebinar.com/register/70352…
Cyber Triage tweet media
English
0
3
4
702
Cyber Triage
Cyber Triage@cybertriage·
Catch DFIR’s Con Artists Thursday’s RMM masterclass: → Commonly abused RMM tools → DFIR artifacts they leave behind → Insights from those artifacts → How to investigate With Professor Mike Wilkinson Register: attendee.gotowebinar.com/register/69551…
Cyber Triage tweet media
English
0
0
1
170
Cyber Triage
Cyber Triage@cybertriage·
New DFIR Research: Chris Ray’s comprehensive list of LogMeIn artifacts ⤵ → Windows events → Registry keys → Exe names → Domains → Log files → Folders Right here: cybertriage.com/blog/dfir-next… P.S. Share this post to help other DFIR pros!
English
0
20
45
1.8K
Cyber Triage
Cyber Triage@cybertriage·
AI in DFIR has “levels” Only one doesn’t involve the investigator: Level 4 The ideal: → Full automation (level 4) for low-risk decisions. → Recommendation (level 3) for higher risk decisions.
Cyber Triage tweet media
English
0
7
14
1.4K
Cyber Triage
Cyber Triage@cybertriage·
Philosoraptor’s easiest question yet! And creators, Mike Cohen and Brian Carrier, explain how to this Thursday. With this integration, Velociraptor scans thousands of endpoints, and Cyber Triage dives into ~20 where the attacker was active. To register: register.gotowebinar.com/register/12891…
Cyber Triage tweet media
English
0
2
5
514