
Standalone DFIR data collector for Windows systems with adaptive collection
Standalone DFIR data collector for Windows systems with adaptive collection
Cyber Triage Collector is a standalone Windows executable that extracts digital forensics and incident response artifacts from live Windows systems. The tool collects over 1,000 artifact types including registry hives, event logs, prefetch files, scheduled tasks, processes, network connections, user activity, and file metadata from NTFS MFT. The collector uses an adaptive collection algorithm that starts from predefined rules and dynamically expands based on discovered artifacts. This approach identifies and collects recently used executables, DLLs, scripts, and potential threat actor tools. The tool requires Windows XP or above and administrator credentials to run. Deployment options include EDR agent push via PowerShell scripts, email distribution, USB drives, or remote shares. The collector outputs a single file that can be saved locally, uploaded to a Cyber Triage server, or sent to cloud object storage including Amazon S3 and Azure Blob. Output files support optional public-key encryption. Collection rules can be customized through the Cyber Triage UI to include specific application logs or indicators of compromise. The tool includes both command-line and GUI interfaces. Collected data can be exported to ZIP format for analysis in other forensic tools. The collector supports network-isolated environments by saving collections to local storage for later import. It includes a Deployer PowerShell script for automated deployment across EDR platforms.
Common questions about Cyber Triage Cyber Triage Collector including features, pricing, alternatives, and user reviews.
Cyber Triage Cyber Triage Collector is Standalone DFIR data collector for Windows systems with adaptive collection, developed by Cyber Triage. It is a Security Operations solution designed to help security teams with Evidence Collection, Windows Forensics, Windows Security.
A PowerShell-based DFIR automation tool that streamlines artifact and evidence collection from Windows machines for digital forensic investigations.
Digital forensics suite for processing, analyzing & reporting computer/mobile data
Accredited forensic cell site geolocation analysis for criminal investigations.
Professional e-discovery service for ESI identification, collection & review.