CYBER TRIAGE
Automated DFIR collection and analysis tool by Basis Technology. Rapidly triages endpoints for compromise indicators.
OVERVIEW#
Cyber Triage automates artifact collection and analysis on Windows endpoints. Scores items as Good, Suspicious, or Bad using threat intelligence, YARA rules, and behavioral analytics.
EDITIONS#
Standard: Single analyst, local analysis Team: Multi-analyst, shared investigations Lite: Free edition with limited features
COLLECTION METHODS#
# 1. Live collection (agent-based) # Deploy collector to target endpoint # Collects artifacts over network # No reboot required # 2. Disk image analysis # Import E01, raw, VHD, VMDK images # Offline analysis of disk contents # 3. KAPE output import # Import KAPE-collected artifacts
ARTIFACTS COLLECTED#
Startup items (Run keys, services, tasks) Running processes and loaded DLLs Network connections and DNS cache User accounts and logon sessions Installed programs and browser history Downloaded files and recent documents Event logs (Security, System, PowerShell) Prefetch files NTFS artifacts ($MFT, USN Journal) WMI persistence Registry (autorun, UserAssist, Shimcache) Amcache entries
SCORING SYSTEM#
Bad (Red) Known malicious (hash match, YARA, etc.) Suspicious (Amber) Anomalous behavior, unknown binaries Good (Green) Known legitimate, signed, common Unknown (Gray) Insufficient data to score # Scores based on: - VirusTotal hash lookups - YARA rule matches - NSRL hash set (known good) - Code signing verification - Behavioral analysis - Threat intelligence feeds
ANALYSIS WORKFLOW#
# 1. Create new session # 2. Select collection method (live, image, KAPE) # 3. Run collection (live) or import (image/KAPE) # 4. Review auto-scored results # 5. Focus on Bad and Suspicious items # 6. Investigate timeline of events # 7. Document findings # 8. Export report
TIPS#
- Start with Bad/Suspicious items for quick wins - Timeline view shows chronological activity - Integrates with VirusTotal for hash reputation - YARA rules catch known malware patterns - Code signing analysis identifies unsigned/tampered binaries - Free Lite edition good for learning and small investigations - Team edition enables collaborative DFIR - KAPE import allows using existing collection workflows - Compare multiple endpoints to find lateral movement - Export reports for incident documentation
CYBER TRIAGE CHEATSHEET ======================== Source: https://cheatsheet.johlem.net Automated DFIR collection and analysis tool by Basis Technology. Rapidly triages endpoints for compromise indicators. OVERVIEW --------- Cyber Triage automates artifact collection and analysis on Windows endpoints. Scores items as Good, Suspicious, or Bad using threat intelligence, YARA rules, and behavioral analytics. EDITIONS --------- Standard: Single analyst, local analysis Team: Multi-analyst, shared investigations Lite: Free edition with limited features COLLECTION METHODS -------------------- # 1. Live collection (agent-based) # Deploy collector to target endpoint # Collects artifacts over network # No reboot required # 2. Disk image analysis # Import E01, raw, VHD, VMDK images # Offline analysis of disk contents # 3. KAPE output import # Import KAPE-collected artifacts ARTIFACTS COLLECTED --------------------- Startup items (Run keys, services, tasks) Running processes and loaded DLLs Network connections and DNS cache User accounts and logon sessions Installed programs and browser history Downloaded files and recent documents Event logs (Security, System, PowerShell) Prefetch files NTFS artifacts ($MFT, USN Journal) WMI persistence Registry (autorun, UserAssist, Shimcache) Amcache entries SCORING SYSTEM ---------------- Bad (Red) Known malicious (hash match, YARA, etc.) Suspicious (Amber) Anomalous behavior, unknown binaries Good (Green) Known legitimate, signed, common Unknown (Gray) Insufficient data to score # Scores based on: - VirusTotal hash lookups - YARA rule matches - NSRL hash set (known good) - Code signing verification - Behavioral analysis - Threat intelligence feeds ANALYSIS WORKFLOW ------------------- # 1. Create new session # 2. Select collection method (live, image, KAPE) # 3. Run collection (live) or import (image/KAPE) # 4. Review auto-scored results # 5. Focus on Bad and Suspicious items # 6. Investigate timeline of events # 7. Document findings # 8. Export report TIPS ----- - Start with Bad/Suspicious items for quick wins - Timeline view shows chronological activity - Integrates with VirusTotal for hash reputation - YARA rules catch known malware patterns - Code signing analysis identifies unsigned/tampered binaries - Free Lite edition good for learning and small investigations - Team edition enables collaborative DFIR - KAPE import allows using existing collection workflows - Compare multiple endpoints to find lateral movement - Export reports for incident documentation
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.