After more than 10 years delivering DFIR services as Incident Handlers and Forensic Analysts, we have been progressively developing our own DFIR analysis system known as SKY.
The SKY platform has been designed to automate most of the usual orchestration work needed to manage a DF/IR/CTI infrastructure. SKY is an automated analysis system that is able to process evidence with specific tools, and to integrate the results in a centralized analysis environment to be reviewed by the designated investigators.
SKY has been a key player in several massive investigations, reaching thousands of systems and terabytes of data, where traditional investigation methodologies and techniques were unable to provide fast and efficient answers.
We have also successfully deployed several of the aforementioned components for DF/IR/CTI teams in law enforcement and the private sector (financial), and they have been able to greatly increase the bandwidth of the team by decreasing the number of cases in their pipeline.
SKY architecture integrates third-party DFIR tools into its workflow easily, automating the execution of the most advanced forensic software.
SKY has a flexible plugin framework that allows new workflows to be developed and facilitates the integration of open-source and commercial tools, whether or not they have an API, based on an understanding of GUI automation.