Empowering Responders with Automated Investigation, a SANS First Look published by SANS Institute in February 2025, examines how Binalyze's Automated Investigation and Response (AIR) platform automates forensic data collection, triage, and threat hunting. The review looks at how AIR's feature set lowers the skill barrier for handling security incidents, allowing analysts without specialized forensic training to work from the same evidence and findings as experienced investigators.
Key findings:
- AIR's Investigation Hub provides a single pane-of-glass dashboard for searching, filtering, bookmarking, and investigating case findings, with comments and an activity feed to support collaborative investigations
- Findings are automatically categorized by severity, high, medium, and low, plus a separate "matched" category tied to defined keywords, hashes, or patterns, so analysts do not have to manually sift through raw evidence
- AIR's built-in DRONE analyzers run an automated compromise assessment that surfaces prioritized, actionable findings instead of requiring analysts to manually identify what is unusual in a case
- The platform can collect more than 600 types of forensic artifacts, including memory dumps, running processes, shell history, and browser history, across Windows, Linux, macOS, and IBM AIX
- Evidence acquisition uses prebuilt profiles, fast scan, full scan, or compromise assessment, letting analysts start a collection with a single click rather than manual configuration
- Full disk imaging, historically a task requiring physical access to a device, can be triggered remotely from the AIR platform, with built-in hashing and RFC 3161 timestamping to preserve chain of custody
- AIR supports precision threat hunting using YARA, Sigma, and Osquery rules, covering malicious binary detection, cross-log activity searches, and SQL-like queries against system data
- The platform includes prebuilt integrations for SIEM, SOAR, and EDR/XDR tools such as Splunk, SentinelOne, and Slack, along with a documented API and webhooks for custom integrations
- All user activity inside AIR is logged, supporting the audit trail requirements of a forensic investigation
The review's overall takeaway is that AIR's value comes from lowering the skill floor for forensic investigation. Rather than requiring a dedicated forensics specialist to interpret raw artifacts, the platform's automated analysis and prioritized findings let general security analysts work incidents that would otherwise need escalation, while still giving experienced investigators a faster, more consolidated workflow through precision hunting and API-driven integrations.
This SANS First Look was written by SANS Certified Instructor and DFIR faculty member Megan Roddie-Fonseca, based on a hands-on evaluation of the Binalyze AIR platform. The paper was sponsored by Binalyze.