7. Integrations¶
Cyber Triage can integrate with several platforms. This page provides links to the instructions for using them.
7.1. Deploy via EDR / Agents¶
You can use EDRs and other agent-based systems to deploy the Cyber Triage Collector. Our Collector is very easy to deploy. It’s a single Windows executable.
The agents from an EDR or other tool (such as Velociraptor) can be used to copy the Collector to the endpoint and to launch it.
7.2. Import Telemetry¶
You can import telemetry data from EDRs. This feature requires a special license.
7.3. SIEMs¶
Cyber Triage can export data that can be imported into Splunk (see All Items JSON Report).
7.4. Case Management¶
The results from an investigation can be pushed back into case management software:
7.5. Other Forensics Tools¶
The output of Cyber Triage can be imported into other tools, such as:
Timesketch (All Items in JSON Line (Timesketch) Report)
Autopsy (Autopsy Integration)
7.6. Scripts¶
You can invoke Cyber Triage from your own scripts using its command line interface.