Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
Forensics to Respond to Incidents Fast and Affordable Automated incident response software allows for quick, thorough, and simple intrusion investigations. An alert is generated by SIEM or IDS. SOAR is used to initiate an endpoint investigation. Cyber Triage is used to collect data at the endpoint. Cyber Triage data is used by analysts to locate evidence and make decisions. The manual incident response process is slow and leaves the entire organization vulnerable to the intruder. Cyber Triage automates every step of the endpoint investigation process. This ensures high-quality remediation speed. Cyber threats change constantly, so manual incident response can be inconsistent or incomplete. Cyber Triage is always up-to-date with the latest threat intelligence and scours every corner of compromised endpoints. Cyber Triage's forensic tools can be confusing and lack features that are necessary to detect intrusions. Cyber Triage's intuitive interface makes it easy for junior staff to analyze data, and create reports.
Description
Xplico is a prominent tool featured in many leading digital forensics and penetration testing distributions, including Kali Linux, BackTrack, DEFT, Security Onion, Matriux, BackBox, CERT Forensics Tools, Pentoo, and CERT-Toolkit. It supports simultaneous access for multiple users, allowing each to manage one or several cases effectively. The interface is web-based, and its backend database options include SQLite, MySQL, or PostgreSQL. Additionally, Xplico can function as a Cloud Network Forensic Analysis Tool. Its primary objective is to extract application data from internet traffic captures, such as retrieving emails via protocols like POP, IMAP, and SMTP, along with HTTP content, VoIP calls through SIP, and file transfers using FTP and TFTP from pcap files. Importantly, Xplico is not classified as a network protocol analyzer. As an open-source Network Forensic Analysis Tool (NFAT), it organizes the reassembled data with an associated XML file that distinctly identifies the data flows and the corresponding pcap file. This structured approach enables users to efficiently analyze and manage the data extracted from network traffic.
API Access
Has API
No
API Access
Has API
No
Integrations
Elastic Security
Yes
IBM Cloud
Yes
IBM QRadar SIEM
Yes
Microsoft Defender for Endpoint
Yes
MySQL
No
SQLite
No
SentinelOne Singularity
Yes
Splunk Cloud Platform
Yes
Splunk SOAR
Yes
Swimlane
Yes
Integrations
Elastic Security
No
IBM Cloud
No
IBM QRadar SIEM
No
Microsoft Defender for Endpoint
No
MySQL
Yes
SQLite
Yes
SentinelOne Singularity
No
Splunk Cloud Platform
No
Splunk SOAR
No
Swimlane
No
Pricing Details
$2,500
Free Trial
Yes
Free Version
Yes
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Deployment
Web-Based
Yes
On-Premises
Yes
iPhone App
No
iPad App
No
Android App
No
Windows
Yes
Mac
No
Linux
Yes
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
Yes
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
Yes
Live Training (Online)
Yes
In Person
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
Yes
In Person
No
Vendor Details
Company Name
Sleuth Kit Labs
Founded
2023
Country
United States
Website
www.cybertriage.com
Vendor Details
Company Name
Xplico
Founded
2007
Website
www.xplico.org
Product Features
Incident Response
Attack Behavior Analytics
Yes
Automated Remediation
Yes
Compliance Reporting
Yes
Forensic Data Retention
Yes
Incident Alerting
Yes
Incident Database
Yes
Incident Logs
Yes
Incident Reporting
Yes
Privacy Breach Reporting
No
SIEM Data Ingestion / Correlation
Yes
SLA Tracking / Management
No
Security Orchestration
No
Threat Intelligence
Yes
Timeline Analysis
Yes
Workflow Automation
Yes
Workflow Management
Yes