@cybertriage

Digital Forensics and incident response software for endpoint investigations. Built by @sleuthkitlabs and Brian Carrier (@carrier4n6).

Cambridge, MA.
Joined December 2014
DFIR is changing fast. How do investigators adapt their approach to stay effective? Today, 11 AM EST, Blake Regan and Brian Carrier debate when and when *not* to use EDR in DFIR, plus provide tools + techniques to use in modern investigations. Register: register.gotowebinar.com/reg…
1
6
1,179
To EDR or not EDR? That’s the investigator’s question. Next Thursday, Blake Regan and Brian Carrier will tackle that and other questions facing SOC and IR teams trying to adapt to emerging threats and evolving tech. Register here: register.gotowebinar.com/reg…
1
3
445
New DFIR Research: Pulseway (RMM) Abuse ⤵ Our team recently observed a threat actor using Pulseway for remote access and gaining full control of a system. Read @MikeWilko's research + investigation tips from the case: cybertriage.com/blog/dfir-ne…
3
4
520
85% of attacks use LOTL The Socrates of SOC investigations teaches his best approach⤵ This Thursday, Wade Wells, detection and response expert, shares: → War stories → Investigation approach → Top 3 tips for elite endpoint triage Register: register.gotowebinar.com/reg…
3
4
718
Catch DFIR’s Con Artists Thursday’s RMM masterclass: → Commonly abused RMM tools → DFIR artifacts they leave behind → Insights from those artifacts → How to investigate With Professor Mike Wilkinson Register: attendee.gotowebinar.com/reg…
1
179
RMMs: The Perfect Diguise. And attackers will get away with it, unless you learn to unmask them. Next Thursday, @MikeWilko will teach you just that. Register: attendee.gotowebinar.com/reg…
4
3
580
Free your mind: Automate your DFIR. Tomorrow, join @carrier4n6 and Chris Ray as they demo the new Defender → Cyber Triage automation. Register: attendee.gotowebinar.com/reg…
1
3
376
New DFIR Research: Chris Ray’s comprehensive list of LogMeIn artifacts ⤵ → Windows events → Registry keys → Exe names → Domains → Log files → Folders Right here: cybertriage.com/blog/dfir-ne… P.S. Share this post to help other DFIR pros!
20
45
1,861
New SOC DFIR Automation ⤵ CyberTriage 3.15 can automatically pull + analyze Defender data. See it live with @carrier4n6 and Chris Ray on September 11. Register: attendee.gotowebinar.com/reg…
2
172
Learn AI basics in DFIR: → AI + LMMs in DFIR overview → When to apply AI to investigations → Live demo of LLM + Cyber Triage Join experts @carrier4n6 and @sidprobstein tomorrow! Register: attendee.gotowebinar.com/reg…
1
3
248
AI in DFIR has “levels” Only one doesn’t involve the investigator: Level 4 The ideal: → Full automation (level 4) for low-risk decisions. → Recommendation (level 3) for higher risk decisions.
7
14
1,403
AI in digital investigations. Learn the basics from these 2 “guys”: → @carrier4n6 → @sidprobstein Register now: attendee.gotowebinar.com/reg…
3
1
6
943
Save this DFIR series: Windows Registry Forensics 2025 ⤵ → Registry Forensics 2025: cybertriage.com/blog/windows… → Forensics Cheatsheet: cybertriage.com/blog/windows… → Forensics Tools: cybertriage.com/blog/2025-gu… P.S. Share this post to help other DFIR pros!
23
70
4,293
Understand investigation automation. @carrier4n6’s framework: cybertriage.com/blog/3-ways-… You can test all 3 automation types with Cyber Triage. Trial copy: cybertriage.com/download-eva…
2
7
859
Philosoraptor’s easiest question yet! And creators, Mike Cohen and Brian Carrier, explain how to this Thursday. With this integration, Velociraptor scans thousands of endpoints, and Cyber Triage dives into ~20 where the attacker was active. To register: register.gotowebinar.com/reg…
2
5
516