For the complete documentation index, see llms.txt. This page is also available as Markdown.

Triage

Collect data for endpoint triage.

Triage enables you to do a in-depth analysis of a specific endpoint to fully understand the activities that occurred on that endpoint. The triage functionality is configurable and supports the collection of all currently supported forensic artifacts, user-defined file paths, a full file listing for all of the connected drives, full event logs, and registry hives. The amount of data collected during a triage can be large, so triages are limited to ten or fewer endpoints per collection.

Create a triage

Use triage collections when a certain activity, group of activities, or the actions of a specific user on that endpoint have been identified, and additional information is required. The triage functionality collects detailed system information, including a full file listing for all of the connected drives, full event logs, and registry hives, to provide you with a complete, holistic picture of an endpoint.

Triage supports data collection from both online and offline hosts, on both Windows and macOS platforms.

  1. In the Triage Collection Name field, enter a name that will be easy to find in the collections table.

  2. Select the Platform either Windows, macOS or Linux.

  3. In the Description field, enter information that is relevant to the collection you are creating .

  4. For Triage Type, you can select Offline or Online or both.

  5. Select Offline to upload archives containing forensic data collected by the Offline Collector. After the archive is uploaded, the data is extracted and ingested into the Forensics tables on the tenant. Import Offline Triage supports uploading packages created on Windows, macOS, and Linux platforms.

  6. Click Save Collection and Exit or click Next to continue.

  7. On the Configuration page, refer to Configure Collection for information about each artifact.

  8. You can select a preset from Select Presets (Windows/macOS/Linux) to copy the options for artifacts, volatiles, and file collections from another collection.

    You can also click Save new preset to save the current collection as a potential triage collection.

  9. Click Save Collection and Exit or click Next to continue.

Upload an offline triage package

The Forensics Triage feature enables you to create a custom, standalone executable package that collects all of the forensic artifacts in the configuration.

Use the Upload Offline Triage to upload archives containing forensic data collected by the offline collector. After the archive has been uploaded, the data is extracted and ingested into the forensics table on the tenant. Upload Offline Triage supports uploading packages created on both the Windows and macOS platforms..

  1. In Cortex Cloud, select Investigation & ResponseForensics.

  2. Click the link of the relevant investigation.

  3. When in the Collections page, search for or select the triage and click the menu options button (menu_options_button.png) to select Upload Offline Package.

  4. Drag and drop or use the browse link to search for the file. More than one offline triage package can be uploaded at a time.

    Note

    Do not upload memory images captured by the Offline Triage Collector. These images are collected for analysis using third-party tools and are not intended for upload.

  5. Click Done.

Offline triage collection

The Forensics add-on provides a triage collection option for endpoints with no network connection or no Cortex XDR agent currently installed.

Note that the procedure differs between Windows, macOS, and Linux.

Windows
  1. Select Investigation & ResponseForensics.

  2. Click the investigation link and from the Collections tab, find the triage and click the menu options button (menu_options_button.png)/ Depending on the system type of the endpoint, select Download 32-bit Collector or Download 64-bit Collector .

  3. Copy the downloaded file to a location accessible from the targeted endpoint.

  4. From the endpoint, open the folder containing the offline triage collector and right-click on the executable file cortex-xdr-payload.exe and select Run as administrator.

    The cortex-xdr-payload.exe opens a command window that displays the status of each artifact collection.

    After the collection is completed, a zip file with the hostname and a timestamp in the file name is created in the same directory as the executable.

  5. From the Collections page, select the triage and click the menu options button (menu_options_button.png) and select Upload Offline Package.

  6. In the Import Offline Triage dialog, browse for or drag and drop the zip file, and click Done.

    The triage file is ingested, and the results are available for review.

    Note

    Security software running on the endpoint (including the Cortex agent) can interfere with or block the execution of the offline triage collector. Disable any security software on the endpoint while the collector is running, or whitelist the collector in your security software before running the offline triage collector.

macOS
  1. Select Investigation & ResponseForensics.

  2. Click the investigation link and from the Collections tab, find the triage and click the menu options button (menu_options_button.png) and select Download Collector.

  3. Open the folder containing the zip file and run the command xattr -c <triage_configuration_name>.zip to remove any extended attributes that macOS might have applied to the file.

  4. Copy the downloaded zip file to a destination that is accessible from the targeted endpoint.

  5. From the endpoint, open the folder containing the offline triage collector and run the cortex-xdr-payload.exe file, or from a command line, enter: sudo cortex-xdr-payload.

    After the collection is completed, a zip file with the hostname and a timestamp in the file name is created in the same directory as the executable.

  6. From the Collections page, select the triage and click the menu options button (menu_options_button.png) and select Upload Offline Package.

  7. In the Import Offline Triage dialog, browse for or drag and drop the zip file, and click Done.

    The triage file is ingested, and the results are available for review.

    Note

    Security software running on the endpoint (including the Cortex agent) can interfere with or block the execution of the offline triage collector. Disable any security software on the endpoint while the collector is running, or whitelist the collector in your security software before running the offline triage collector.

Linux
  1. Select Investigation & ResponseForensics.

  2. Click the investigation link and from the Collections tab, find the triage and click the menu options button (menu_options_button.png) and select Download x86 Collector or Download ARM64 Collector.

  3. Copy the downloaded zip file to a destination that is accessible from the targeted endpoint.

  4. From the endpoint, open the folder containing the offline triage collector and run the cortex-xdr-payload file, or from a command line, enter: sudo ./cortex-xdr-payload.

    After the collection is completed, a zip file with the hostname and a timestamp in the file name is created in the same directory as the executable.

  5. From the Collections page, select the triage and click the menu options button (menu_options_button.png) and select Upload Offline Package.

  6. In the Import Offline Triage dialog, browse for or drag and drop the zip file, and click Done.

    The triage file is ingested, and the results are available for review.

    Note

    Security software running on the endpoint (including the Cortex agent) can interfere with or block the execution of the offline triage collector. Disable any security software on the endpoint while the collector is running, or whitelist the collector in your security software before running the offline triage collector.

Triage results

The Triage collection results page provides an overview of the different types of triage collections initiated on an endpoint.

The triage results page is divided into the following tabs:

  • Artifacts: Display all of the artifact categories collected. Refer to Hunt Results for more information on the artifacts.

  • Host Timeline: Displays a list of normalized, per-host timelines that include multiple forensic artifacts in a single table.

Triage status

You can drill down to the Actions table from the status link of the triage to view the search the status of all the artifacts for the triage.

Field
Description

Endpoint name

Agent hostname.

Endpoint ID

Agent unique ID.

Action ID

Unique identifier for this agent action.

Type

Type of collection.

Example: Amcache, File Collection, Event Logs

Path

Path for files, registry path for registry artifacts.

Status

Displays one of the following statuses of the search:

  • Pending: agent action sent

  • In progress: SAM not sent

  • Results received: received SAM results

  • Timeout: SAM timed out

  • Ingesting: Ingestion started

  • Uploaded: data received, but not parsed

  • Ingested: ingestion completed

  • Partially ingested: ingested with errors

  • Failed: ingestion failed

Details

Shows the detailed output from the ingestion script.

Example: Ingested X of Y records

Collected

Time the data was collected.

Download expiration

Time when bucket data (raw files) is to be deleted.

Preset

Name of the triage configuration.

Collection Type

Collection type.

Triage ID

Unique ID associated with this triage data.

Last updated

Was this helpful?