Brian Carrier
carrier4n6.bsky.social
Brian Carrier
@carrier4n6.bsky.social
#DFIR Automation Series

I use 4 levels of automation ranging from none to fully automated.

I think an ideal solution is to use full automation for low risk decisions. And recommendations for higher risk.

We use recommendations in Cyber Triage by scoring each artifact. You ultimately decide.
August 20, 2025 at 4:10 PM
Digital forensics has always relied on automation and "push buttons". What's changed is how many things we automate and the technologies used.

No one ever chose to manually parse FAT12 floppy drives with a hex editor when they could have a tool list out the file names.
August 13, 2025 at 3:17 PM
Webinar Tomorrow - Automation and AI in DFIR and the SOC.

Myself, Sentinel1, and CompassMSP will talk about pros/cons of automating DFIR and SOC tasks.

Come tell us we're wrong!

May 8. 11AM Eastern.

register.gotowebinar.com/register/672...
May 7, 2025 at 3:51 PM
EDR Evasion 101 - Blocking

Data needs to get to the EDR server to be analyzed for attacks. Blocking techniques prevent data from getting to the server.

Example: Network filter to block packets destined to the server.

www.cybertriage.com/edr_evasion
May 1, 2025 at 3:29 PM
EDR Evasion 101
Types of Evasion Tactics

1) Blinding - prevent agent from seeing
2) Blocking - prevent data from analysis
3) Hiding - prevent detections

www.cybertriage.com/blog/how-edr...
April 16, 2025 at 5:20 PM
Learn from 4 IR experts on how they do Endpoint Triage.

Apr 17.

I'll MC and you'll hear from @keydet89.bsky.social (Huntress), Kai Thomsen (Dragos), @dfirmike.bsky.social (Sleuth Kit Labs) and Quinnlan Varcoe (Blueberry Security).

See you there!

register.gotowebinar.com/register/600...
April 1, 2025 at 4:04 PM
3 places to automate #DFIR Endpoint Triage. Which do you do?
February 11, 2025 at 4:00 PM
The 3 themes we focus on for #DFIR endpoint triage. What are yours?
February 4, 2025 at 9:47 PM
February 3, 2025 at 6:48 PM
January 31, 2025 at 2:23 PM
Endpoint triage allows you to prioritize your response after an EDR alert.

Webinar: Tomorrow at 11 - Vendor Agnostic
register.gotowebinar.com/register/142...
January 29, 2025 at 2:28 PM
Endpoint Triage: What you do after you validate the EDR alert to understand the impact.

#DFIR Webinar Thu @ 11.

register.gotowebinar.com/register/142...
January 28, 2025 at 4:14 PM