Triage ID
Extract Digital Evidence in minutes, not days or weeks
Triage-ID is the most powerful field based triage and data exploitation tool to extract digital intelligence from suspect computers. The tool utilizes a bootable CD and a USB drive for data extraction.
Highlights of Triage-ID
- Offers real time actionable intelligence in minutes
- Accommodates all user levels
- Delivers forensically sound data exploitation
- Provides the ability to target high profile areas of suspect computers
- Integrates the patent pending SearchPak technology to capture and automate identification of conclusive intelligence
- SearchPaks identify specific keywords, phrases, regular expressions, known suspect files (signature based malware/intrusion), illegal or suspect images, suspicious applications (steganography, encryption, anti-forensic) and other file types
- Integrates pixel based image matching technology to identifies suspect images
Triage Lab
Extract Digital Evidence in minutes, not days or weeks
Triage-Lab is a one of a kind field and lab tool that performs automated analysis of drive images, network drives, stand alone live suspect computers, DVD’s, CD’s, and other removable media.
Highlights of Triage-Lab
- Windows based tool that can be deployed on a laptop for field operations
- Offers operators immediate access to data, and allow examiners to prioritize backlogged cases
- Accommodates all user levels
- Integrates the patent pending SearchPak technology to capture and automate identification of conclusive intelligence
- SearchPaks identify specific keywords, phrases, regular expressions, known suspect files (signature based malware/intrusion), illegal or suspect images, suspicious applications (steganography, encryption, anti-forensic) and other file types
- Integrates pixel based image matching technology to identifies suspect images
Triage-Live
Immediately Collect and Analyze Volatile Data
Triage-Live captures information about the current state of a computer before powering it down (or if powering it down is not an option). Before pulling the plug on a target computer to run Triage-ID or seize the machine, the user can plug Triage-Live into the computer and capture the volatile data off before it disappears. The tool is deployed on a secure USB drive.
Highlights of Triage-Live
- Captures physical memory
- Captures clipboard
- Captures device list
- Captures state of encrypted drives
- Captures a list of installed applications
- Captures open network ports
- Captures users recent run command, desktop searches and browser searches
- Captures general system information
- Captures user list and login information
- And more...
Click the image for a pdf specification sheet