In partnership with

Endpoint intrusion investigation that collects, scores, and prioritizes DFIR evidence

Cyber Triage comes from Sleuth Kit Labs, which became an independent company in October 2023 when it spun out of Basis Technology. Its chief executive is Dr. Brian Carrier, who spent eighteen years at Basis leading the digital forensics group and serving as chief technology officer, holds a PhD from Purdue, and wrote The Sleuth Kit and Autopsy, the open source tools that a large share of working forensic examiners learned on. That lineage matters to the product: the company builds for the investigator at the keyboard rather than for a dashboard someone else will read.

The platform addresses the bottleneck in endpoint intrusion work, which is not collection but triage. A collector gathers artifacts from a live host, a disk image, or EDR telemetry, and the analysis engine scores each item against more than 40 malware engines plus heuristics covering persistence, execution, accounts, and network activity. Items are classified as bad, suspicious, good, or unknown so an examiner starts from the small set that warrants attention instead of a full artifact dump. Timeline views and recommendations for related data guide the next query, and findings export to case management platforms and SIEMs so a host investigation feeds back into the wider incident. Users include corporate IR and SOC teams, consultants, MSSPs, and law enforcement.

Market Segments:

Security OperationsEndpoint Security

Categories:

Incident ResponseDigital ForensicsThreat Intelligence