//
sign in
Profile
by @danabra.mov
Profile
by @dansshadow.bsky.social
Profile
by @jimpick.com
AviHandle
by @danabra.mov
AviHandle
by @dansshadow.bsky.social
AviHandle
by @katherine.computer
EventsList
by @katherine.computer
ProfileHeader
by @dansshadow.bsky.social
ProfileHeader
by @danabra.mov
ProfileMedia
by @danabra.mov
ProfilePlays
by @danabra.mov
ProfilePosts
by @danabra.mov
ProfilePosts
by @dansshadow.bsky.social
ProfileReplies
by @danabra.mov
Record
by @atsui.org
Skircle
by @danabra.mov
StreamPlacePlaylist
by @katherine.computer
+ new component
Profile
Loading...









Loading...
New Forensic Resource What to do after you find TeamViewer: → Log files to find activity details → Executables to find installation times → Domains to find download source Learn how to corroborate timelines to investigate suspicious TeamViewer. www.cybertriage.com/blog/dfir-ne...
10mo
DFIR Next Steps: Suspicious TeamViewer Use
Welcome to the next post in our DFIR Next Steps series on Remote Monitoring & Management (RMM) tools. This series is designed to help you quickly
www.cybertriage.com
Cyber Triage
I'm doing a webinar TMRW on investigation tools for endpoint triage. Basic idea is how to get quick and accurate results after an alert. EDR data plays a role in that, but it's not enough. Endpoint Triage should be in any security team's process. attendee.gotowebinar.com/register/281...
The 3 themes we focus on for #DFIR endpoint triage. What are yours?
EDRs miss activity! 😲😱. You should not miss webinar tmrw! 😀 Markus and I will talk about why EDR alerts could be days after an attack started. We'll talk about how to do endpoint triage to see what else happened beyond the alert! Mar 27 @ 11 Eastern register.gotowebinar.com/register/916...
Feb 25, 2025
For those in the #SOC: Alert Triage vs Endpoint Triage Blog post that is part of our Endpoint Triage series. Alert triage focuses on validating and prioritizing the EDR/SIEM alert. Endpoint triage focuses on prioritizing the host. How bad is it? www.cybertriage.com/blog/alert-t...
Feb 4, 2025
Mar 26, 2025
Mar 21, 2025
New Cyber Triage release with: * New UIs to give you an overview of the endpoint * Hyabusa integration * Baseline * Public key encryption on collector * LOTS more.... Blog and Download Link: www.cybertriage.com/blog/3-14-re...
3 places to automate #DFIR Endpoint Triage. Which do you do?
#DFIR Automation Series I use 4 levels of automation ranging from none to fully automated. I think an ideal solution is to use full automation for low risk decisions. And recommendations for higher risk. We use recommendations in Cyber Triage by scoring each artifact. You ultimately decide.