SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsIncident handlers may find themselves in situations where they need to validate a potential compromise but do not have administrative access to the systems in question or in situations where many systems need to be triaged quickly. This may leave the incident handler trying to relay commands to a system administrator or taking valuable time to triage each system individually. This communication and initial triage can be time sensitive and may be inaccurate if the data collection commands are not run as directed. This paper introduces the RapidTriage Python tool which can be used to automate intrusion discovery, speeding up the initial triage and ensuring consistency in the collected results across multiple systems and different platforms.