Triaging at scale

  • The artifact exchange contains many artifacts

    • Some are very simple
    • But we need to remember to collect them all!
  • When triaging an endpoint we want to quickly answer some questions

    • What happened here (Forensics)
    • What bad happened here (Detection)
  • Ideally a fire and forget approach

    • Easy to use - lots of impact!
1
Triaging at scale The artifact exchange contains many artifacts Some are very simple But we need to remember to collect them all! When triaging an endpoint we want to quickly answer some questions What happened here (Forensics) What bad happened here (Detection) Ideally a fire and forget approach Easy to use - lots of impact!