← All cheat sheets

CYBER TRIAGE

Plain-text reference · 3 KB. Read it, search it (Ctrl-F) or print it.

Automated DFIR collection and analysis tool by Basis Technology.
Rapidly triages endpoints for compromise indicators.

OVERVIEW#

Cyber Triage automates artifact collection and analysis on Windows
endpoints. Scores items as Good, Suspicious, or Bad using threat
intelligence, YARA rules, and behavioral analytics.

EDITIONS#

  Standard:  Single analyst, local analysis
  Team:      Multi-analyst, shared investigations
  Lite:      Free edition with limited features

COLLECTION METHODS#

# 1. Live collection (agent-based)
#    Deploy collector to target endpoint
#    Collects artifacts over network
#    No reboot required

# 2. Disk image analysis
#    Import E01, raw, VHD, VMDK images
#    Offline analysis of disk contents

# 3. KAPE output import
#    Import KAPE-collected artifacts

ARTIFACTS COLLECTED#

  Startup items (Run keys, services, tasks)
  Running processes and loaded DLLs
  Network connections and DNS cache
  User accounts and logon sessions
  Installed programs and browser history
  Downloaded files and recent documents
  Event logs (Security, System, PowerShell)
  Prefetch files
  NTFS artifacts ($MFT, USN Journal)
  WMI persistence
  Registry (autorun, UserAssist, Shimcache)
  Amcache entries

SCORING SYSTEM#

  Bad (Red)         Known malicious (hash match, YARA, etc.)
  Suspicious (Amber) Anomalous behavior, unknown binaries
  Good (Green)      Known legitimate, signed, common
  Unknown (Gray)    Insufficient data to score

# Scores based on:
  - VirusTotal hash lookups
  - YARA rule matches
  - NSRL hash set (known good)
  - Code signing verification
  - Behavioral analysis
  - Threat intelligence feeds

ANALYSIS WORKFLOW#

# 1. Create new session
# 2. Select collection method (live, image, KAPE)
# 3. Run collection (live) or import (image/KAPE)
# 4. Review auto-scored results
# 5. Focus on Bad and Suspicious items
# 6. Investigate timeline of events
# 7. Document findings
# 8. Export report

TIPS#

  - Start with Bad/Suspicious items for quick wins
  - Timeline view shows chronological activity
  - Integrates with VirusTotal for hash reputation
  - YARA rules catch known malware patterns
  - Code signing analysis identifies unsigned/tampered binaries
  - Free Lite edition good for learning and small investigations
  - Team edition enables collaborative DFIR
  - KAPE import allows using existing collection workflows
  - Compare multiple endpoints to find lateral movement
  - Export reports for incident documentation

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.