Talk to a Binalyzer
Get a free trial
Whether you are investigating an endpoint in your corporate environment or you are part of a criminal investigation, you need to investigate the USB device history of an endpoint. Knowing what USB devices were connected to the computer is the essential information and of great importance to a forensic examiner.
When responding to a cybersecurity incident, spending a lot of time analyzing forensic artifacts is a luxury that none of us have. Let’s say you have an incident in an organization with thousands of servers and clients, analyzing the compromised environment will take weeks, even months.
In the past month, we released a new version of AIR that includes the new Cases management feature that gives you the ability to manage and create new individual cases for your investigations on a completely self-service basis to increase the speed and efficiency of your investigations
With the latest version of Binalyze AIR, you can export endpoints, case information, timelines, and audit logs to CSV. How does it work?
Compromise assessment is an analysis of a network of endpoints or a single endpoint to uncover unknown security breaches, malware, and any sign of unauthorized access. The assessment seeks to discover any present and past attacker traces in the environment.
Microsoft patches actively exploited Exchange, Excel zero-days (CVE-2021-42321). Please refer to their site for more details.
When we plan our incident response strategies and forensic readiness steps, we strongly pay attention to digital evidence acquisition, storage, handling, reporting, and remediation.
The purpose of an investigation is never just to find the source of damage and place a quick repair. An investigation is in place to find out how it happened, document it, and fix those circumstances so they don’t occur again.
Binalyze is delighted to announce we are joining the EU’s ECHO Network project as a vendor, making us the first Digital Forensics and Incident Response participant in this network.
Welcome to our monthly product updates roundup! Here’s a rundown of the new features and solutions we released in the past month that you can now take advantage of.
The end goal of this step is to ensure that internal training & awareness programs take place within your organization since your employees may be involved in the process of handling security incidents.
There can be many kinds of suspicious events generated either by the system or by human watchfulness. Every suspicious event (as described in step 6) needs to be checked before launching a full formal investigation.