Cyber Triage
AI-powered digital forensics platform that ingests endpoint and EDR evidence, scores artifacts, and recommends related data to investigate intrusions and assess threats
An AI-powered digital forensics and incident investigation platform that ingests evidence from endpoints, EDR telemetry, SIEMs and disk images, scores artifacts as bad/suspicious/good/unknown, and recommends related items to find root cause and complete threat assessments. It sells to SOC analysts, internal IR and DFIR teams, IR consultants and MSSPs, and law enforcement intrusion teams in mid-market to enterprise and government organizations. Positioned as complementing EDR by analyzing forensic evidence EDRs miss and scoring artifacts using more detections than other DFIR tools, delivered as a SaaS platform with endpoint collectors and integrations.
Key features
- Endpoint data collection via The Collector
- Ingest EDR telemetry and SIEM data
- Ingest disk images
- Automated artifact scoring (bad/suspicious/good/unknown)
- 40+ malware engines scanning
- YARA and Hayabusa rules
- Hybrid AI scoring and recommendations
- Related items and timeline analysis
- Malware detection
- Ransomware detection
- Sandbox analysis
- Server API
- EDR integrations
- Malware Scanner for Autopsy
- LinkedIn0.3/day
- Blog
- Marketplace
- API
- Creative ads
- Security teams
- IT teams
- Government public sector