Triager: An Open-Source Platform for Automated Forensic Triage and Investigation

  • Cristian H. M. Souza Kaspersky / USP
  • Eduardo O. Chavarro Kaspersky
  • Daniel M. Batista USP

Resumo


Digital Forensics and Incident Response (DFIR) investigations commonly require analysts to process heterogeneous Windows artifacts, execute multiple specialized parsers, normalize their outputs, and correlate evidence across several endpoints under strict time constraints. This paper presents Triager, an open-source DFIR automation and investigation platform for Windows triage collections. Triager orchestrates evidence extraction, performs artifact analysis, normalizes results into CSV files, and organizes the findings in a consistent investigation-ready structure. The Web Console imports these results into per-case databases and provides multi-case and multi-machine management, indexed search, filtering, cross-host correlation, unified timelines, IOC scanning, AI-assisted analysis, evidence export, and report generation. By integrating evidence processing and investigation management, Triager reduces repetitive operational work while preserving the use of specialized forensic parsers for artifact extraction.

Referências

Chand, R. R., Sharma, N. A., and Kabir, M. A. (2025). Advancing web browser forensics: Critical evaluation of emerging tools and techniques. SN Computer Science, 6(4):355.

Dieterich, A., Schopp, M., Stiemert, L., Steininger, C., and Pöhn, D. (2023). Evaluation of persistence methods used by malware on microsoft windows systems. In ICISSP, pages 552–559.

Easttom, C., Butler, W., Phelan, J., Bhagavatula, R. S., Steuber, S., Rodriguez, K., Balkissoon, V. I., and Naseer, Z. (2024). Windows Forensics. Springer.

Javed, A. R., Ahmed, W., Alazab, M., Jalil, Z., Kifayat, K., and Gadekallu, T. R. (2022). A comprehensive survey on computer forensics: State-of-the-art, tools, techniques, challenges, and future directions. IEEE Access, 10:11065–11089.

Joo, D., Lee, J., and Jeong, D. (2023). A reference database of windows artifacts for file-wiping tool execution analysis. Journal of forensic sciences, 68(3):856–870.

Nelson, A., Rekhi, S., Souppaya, M., and Scarfone, K. (2025). Incident response recommendations and considerations for cybersecurity risk management. NIST special publication.

Neyaz, A. and Shashidhar, N. (2022). Windows prefetch forensics. In Breakthroughs in Digital Biometrics and Forensics, pages 191–210. Springer.

Połczyński, P. (2023). Analysis of event logs in computers (windows systems).

Sharikov, P. and Mokrinskii, N. (2025). Analyze windows logs to investigate phishing attack. In 2025 International Ural Conference on Electrical Power Engineering (UralCon), pages 668–672. IEEE.

Sondarva, K. S., Kumar, A., Gohil, B. N., Patel, S. J., Rajvansh, S., and Shah, R. T. (2023). Forensics analysis of ntfs file systems. In Advances in Cyberology and the Advent of the Next-Gen Information Revolution, pages 138–165. IGI Global Scientific Publishing.

Souza, C. (2025). Forensic journey: hunting evil within amcache. Technical report, Kaspersky Securelist.

Souza, C. H., Chavarro, E. O., and Batista, D. M. (2026). Amcache-evilhunter: Automating evidence of execution extraction from the amcache.hve artifact. In Anais Estendidos do XXVI Simpósio Brasileiro de Cibersegurança, Porto Alegre, RS, Brasil. SBC.

Souza, C. H., Pascoal, T., Neto, E. P., Sousa, G. B., SL Filho, F., Batista, D. M., and Silva, F. S. D. (2025). Sdn-based solutions for malware analysis and detection: State-of-the-art, open issues and research challenges. Journal of Information Security and Applications, 93:104145.
Publicado
01/09/2026
SOUZA, Cristian H. M.; CHAVARRO, Eduardo O.; BATISTA, Daniel M.. Triager: An Open-Source Platform for Automated Forensic Triage and Investigation. In: SALÃO DE FERRAMENTAS - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 251-259. DOI: https://doi.org/10.5753/sbseg_estendido.2026.33554.