less than 1 minute read

Project: Automated Network Triage (ANT) / Profiler
Purpose: Client-server based triage of suspect systems for case relevance sorting
Status: Active
License: 
Developer(s): Martin Koopmans

More information:
ANT is a tool to conduct triage (artifact sorting) on-scene in large corporate networks. ANT is also very useful in a forensic lab to help reduce backlogs.

ANT has been developed using a client-server model, where the network clients will boot from a forensically sound Linux OS that is served by the ANT server using PXE. With ANT it's easy to find targeted suspect data on network clients that can be centrally analyzed on the ANT server.

Profiler is an extension has been developed to get a fast overview of information on a system before starting a full investigation. Profiler parses all Windows Registry files (sam, system, software, security) and Internet files (Chrome, Firefox, Safari and Internet Explorer). Profiler reads EWF images, DD images and physical disks.

Profiler functions have been integrated into ANT.

Related Publications:

Links: