Rapid Triage: Automated System Intrusion Discovery with Python

by Trenton Bond
Sept. 1, 2017 0 comments SANS Institute tools

Incident handlers may find themselves in situations where they need to validate a potential compromise but do not have administrative access to the systems in question or in situations where many systems need to be triaged quickly. This may leave the incident handl er trying to relay commands to a system administrator or taking valuable time to triage each system individually. This communication and initial triage can be time sensitive and may be inaccurate if the data collection commands are not run as d irected. Thi s paper introduces the RapidTriage Python tool which can be used to automate intrusion discovery , speeding up the initial triage and ensuring consistency in the collected results across multiple systems and different platforms.