Cyber Triage
Allows you to conduct a mini-forensic investigation on an endpoint. It pushes a collection tool to the remote endpoint, collects volatile and file system data, and analyzes the data.
- Category
- Endpoint
- Pack
- CyberTriage
Configuration parameters
- server — Hostname of Cyber Triage server (e.g. 192.168.1.2) (required)
- rest_port — REST Port (required)
- api_key —
- credentials — Username (required)
- use_proxy — Use proxy
Commands (1)
- ct-triage-endpoint — initiates a cyber triage collection on an endpoint.