Triage – concept and procedures
The amount of evidence around a cybercrime scene can be overwhelming, and the time available to perform first response procedures is limited. We also need to consider containment of the attack, and ensuring business continuity is vital for organizations. That's why the incident responder needs to identify and prioritize which forensic artifacts can provide useful information to the case.
The process of classification and prioritization is known as triage, and according to Oxford Languages, triage (from the French trier, which means to separate out) is defined as the action of sorting items according to quality. This term is used regularly in some professional fields such as healthcare.
In digital forensics, this prioritization is known as forensic triage. It refers to identifying, classifying, prioritizing, and acquiring evidence relevant to investigate the case. Doing it properly can be the difference between an investigation being...