Talk With an Expert

Rapid Triage: Automated System Intrusion Discovery with Python

Rapid Triage: Automated System Intrusion Discovery with Python (PDF, 3.91MB)Published: 21 Feb, 2014
Created by
Trenton Bond

Incident handlers may find themselves in situations where they need to validate a potential compromise but do not have administrative access to the systems in question or in situations where many systems need to be triaged quickly. This may leave the incident handler trying to relay commands to a system administrator or taking valuable time to triage each system individually. This communication and initial triage can be time sensitive and may be inaccurate if the data collection commands are not run as directed. This paper introduces the RapidTriage Python tool which can be used to automate intrusion discovery, speeding up the initial triage and ensuring consistency in the collected results across multiple systems and different platforms.