Triage
Collect data for endpoint triage.
Triage enables you to do a in-depth analysis of a specific endpoint to fully understand the activities that occurred on that endpoint. The triage functionality is configurable and supports the collection of all currently supported forensic artifacts, user-defined file paths, a full file listing for all of the connected drives, full event logs, and registry hives. The amount of data collected during a triage can be large, so triages are limited to ten or fewer endpoints per collection.
Create a triage
Use triage collections when a certain activity, group of activities, or the actions of a specific user on that endpoint have been identified, and additional information is required. The triage functionality collects detailed system information, including a full file listing for all of the connected drives, full event logs, and registry hives, to provide you with a complete, holistic picture of an endpoint.
Triage supports data collection from both online and offline hosts, on both Windows and macOS platforms.
In the Triage Collection Name field, enter a name that will be easy to find in the collections table.
Select the Platform either Windows, macOS or Linux.
In the Description field, enter information that is relevant to the collection you are creating .
For Triage Type, you can select Offline or Online or both.
Select Offline to upload archives containing forensic data collected by the Offline Collector. After the archive is uploaded, the data is extracted and ingested into the Forensics tables on the tenant. Import Offline Triage supports uploading packages created on Windows, macOS, and Linux platforms.
Click Save Collection and Exit or click Next to continue.
On the Configuration page, refer to Configure Collection for information about each artifact.
You can select a preset from Select Presets (Windows/macOS/Linux) to copy the options for artifacts, volatiles, and file collections from another collection.
You can also click Save new preset to save the current collection as a potential triage collection.
Click Save Collection and Exit or click Next to continue.
Upload an offline triage package
The Forensics Triage feature enables you to create a custom, standalone executable package that collects all of the forensic artifacts in the configuration.
Use the Upload Offline Triage to upload archives containing forensic data collected by the offline collector. After the archive has been uploaded, the data is extracted and ingested into the forensics table on the tenant. Upload Offline Triage supports uploading packages created on both the Windows and macOS platforms..
In Cortex Cloud, select Investigation & Response → Forensics.
Click the link of the relevant investigation.
When in the Collections page, search for or select the triage and click the menu options button (
) to select Upload Offline Package.Click Done.
Offline triage collection
The Forensics add-on provides a triage collection option for endpoints with no network connection or no Cortex XDR agent currently installed.
Note that the procedure differs between Windows, macOS, and Linux.
Triage results
The Triage collection results page provides an overview of the different types of triage collections initiated on an endpoint.
The triage results page is divided into the following tabs:
Artifacts: Display all of the artifact categories collected. Refer to Hunt Results for more information on the artifacts.
Host Timeline: Displays a list of normalized, per-host timelines that include multiple forensic artifacts in a single table.
Triage status
You can drill down to the Actions table from the status link of the triage to view the search the status of all the artifacts for the triage.
Endpoint name
Agent hostname.
Endpoint ID
Agent unique ID.
Action ID
Unique identifier for this agent action.
Type
Type of collection.
Example: Amcache, File Collection, Event Logs
Path
Path for files, registry path for registry artifacts.
Status
Displays one of the following statuses of the search:
Pending: agent action sent
In progress: SAM not sent
Results received: received SAM results
Timeout: SAM timed out
Ingesting: Ingestion started
Uploaded: data received, but not parsed
Ingested: ingestion completed
Partially ingested: ingested with errors
Failed: ingestion failed
Details
Shows the detailed output from the ingestion script.
Example: Ingested X of Y records
Collected
Time the data was collected.
Download expiration
Time when bucket data (raw files) is to be deleted.
Preset
Name of the triage configuration.
Collection Type
Collection type.
Triage ID
Unique ID associated with this triage data.
Last updated
Was this helpful?
