What is a forensic triage artefact set, and how does it differ from a full disk image?
answer
- coverage across hosts beats depth on one
- selected files, not sectors
- minutes and megabytes per host
- no unallocated space or deleted content
- triage scopes, imaging proves
basics
~20 sA triage artefact set copies a chosen list of high-value host artefacts - event logs, execution and persistence records, scheduled tasks - instead of every sector of the disk. Minutes and megabytes per host rather than hours and terabytes, so it scales to hundreds of machines.
solid answer
~50 sA full disk image is a bit-for-bit copy of a storage device: everything, including deleted files and unallocated space. A triage artefact set is a targeted collection of named artefacts from a live host - Windows event logs, prefetch and other execution artefacts, run keys and scheduled tasks, service definitions, browser and shell history, filesystem metadata such as the MFT - packaged and shipped off the host. The point is arithmetic. Imaging one 512 GB laptop takes hours and produces a file you then have to store and process; a triage profile takes single-digit minutes and tens to hundreds of megabytes, which is the only thing that works when the question is `which of these 900 endpoints ran the lure`. You give up deleted content, slack and unallocated space, and anything the profile did not name. So triage is how you find the handful of hosts that matter; imaging is what you do to those hosts afterwards, if the case needs it.
go deeper
Be ready to list what a triage profile actually pulls from a host and to state the size and time difference against imaging in one sentence. Knowing that unallocated space is not in it is the detail interviewers listen for.
Explain the mechanics: which artefacts answer which question, why filesystem metadata survives a deleted file, and what running a collector on a live host changes on that host.
Show the funnel judgment - sweep wide to scope, image narrow to prove - and be able to say which host you would promote from triage to a full acquisition and why.
Own the cost side: storage, analyst hours and the standing tooling needed to collect at estate scale, and be able to defend to counsel why you did not image everything.
## The two things being compared A **full disk image** is a bit-for-bit copy of a storage device, sector by sector, including regions the filesystem no longer references: deleted files not yet overwritten, file slack, unallocated space, and in some cases host-protected areas. Nothing is selected, so nothing is missed - which is exactly why it is expensive. Acquisition speed is bounded by the device and the interface; a 512 GB laptop drive is typically hours, and you then own an image of that size for the life of the case, plus the processing time to index it. A **triage artefact set** (also called a triage collection, or forensic triage) is a *selective* copy of named, high-value artefacts taken from a running host. A typical Windows profile pulls the Security, System, Application, PowerShell and Sysmon event logs; the MFT and USN journal (filesystem metadata, which tells you a file existed and when even if its content is gone); prefetch and other execution evidence; registry hives carrying run keys, services and installed software; scheduled task definitions; shell and browser history; and a process, service and network snapshot taken at collection time. On Linux the equivalent is `/var/log`, audit logs, shell histories, cron and systemd unit files, package state and process listings. The set is packaged - usually as a single archive with a manifest - and shipped to your analysis store. ## Why you would ever choose the lossy option Because the first question in a wide incident is almost never *what exactly happened on this one box*. It is *which boxes are in scope at all*. If a third-party application was granted a mail-read scope across your tenant after a consent lure, you do not know how many of your endpoints saw the lure or what else the user ran afterwards. You cannot answer that by imaging; you answer it by pulling the same small profile from every endpoint in parallel and looking for the outliers. The arithmetic is what makes the decision, and it is worth being able to say out loud in an interview: | | Full image | Triage set | |---|---|---| | Time per host | Hours | Minutes | | Size per host | Hundreds of GB | Tens-hundreds of MB | | Hosts you can do at once | One, maybe a few | The whole estate | | Deleted / unallocated data | Yes | No | | Anything not in the profile | Present | Gone | | Host must be taken out of service | Usually | No | ## What you are actually giving up Be precise here, because this is where candidates overclaim in both directions. - **You lose unallocated space and file slack.** Deleted-file *content* is generally not recoverable from a triage set. You often still see that a file *existed*, because filesystem metadata such as the MFT and USN journal is collected and survives the file itself. - **You lose anything the profile did not name.** A profile written before the case cannot anticipate a case-specific artefact - an application log for a niche product, a particular user directory. Good tooling lets you extend the profile per case; that is a decision, not a default. - **You do not lose defensibility.** A triage collection is ordinary digital evidence: it is admissible if you can say what you collected, when, from where, with what tool, and can show the copy is unchanged since. Selectivity is a *completeness* limitation you disclose, not an authenticity defect. The common wrong answer is that triage output is somehow not `real forensics`. - **Collection is not free of footprint.** Anything you run on a live host writes to that host and changes volatile state. That is a known and accepted cost of live collection, and it is the reason your notes must record exactly what you ran. ## How the two fit together in practice The normal shape of a large investigation is a funnel. A wide triage sweep across the estate produces a small set of hosts with something interesting. Those hosts get deeper treatment - a fuller collection, memory, or a genuine image - and that is where the expensive, complete acquisition is justified because the population is now small. Running it the other way round - insisting on images first - fails in two ways at once: it is too slow to scope the incident before the adversary acts again, and it burns your responders on 899 machines that turn out to be irrelevant. The judgment an interviewer is testing is whether you understand that *completeness per host* and *coverage across hosts* are competing goods, and that early in an incident coverage usually wins.
- If a triage set does not carry deleted file content, how can it still show that a file was there?Because filesystem metadata is collected alongside the files. On Windows the MFT and the USN change journal record that an entry existed, its timestamps and its size, and journal entries persist after the file is deleted. That supports a claim about existence and timing, not about content - to recover the content itself you need the image.
- Does a triage collection give up admissibility compared with an image?No. Admissibility turns on being able to say what was collected, by whom, when, with which tool, and to show the copy has not changed since. A selective collection is a stated limitation on completeness, which you disclose, not a defect in authenticity. Opposing counsel may argue you missed something; that is answered with your collection notes and, if needed, a later image.
- When would you refuse to triage and insist on imaging instead?When the host is already the confirmed subject rather than a candidate, and the questions ahead need what triage discards: recovering deleted content, anti-forensic wiping, or a case likely to end in litigation or an employment dispute where completeness will be attacked. Small population plus high evidentiary stakes is exactly when the expensive acquisition is worth it.
Investigating a chain of shops, you do not ship every building to the lab. You take the till roll, the door log and the camera clips from all ninety branches, then take the one branch that looks wrong apart properly.
saying these in an interview costs you the question
- Calls a triage set just a faster disk image
- Claims triage collection recovers deleted files and unallocated space
- Says triage output is not admissible or not real forensics
- Insists every host must be imaged before drawing conclusions
- Thinks a triage collection leaves no footprint on the host