Region: Global

Scaled Triage

Company Overview

Headquartered in Vancouver, CyberClan provides its global customers with first-class Breach Response services. Their portfolio of services broadly covers cyber extortion, ransomware, e-discovery, tailored risk management consultancy services, and unparalleled managed security services.

When customers call CyberClan today, most are in the middle of an active incident and require quick assistance and resolution. As a remote company providing services to small security teams and having an industry-leading response time commitment of 15 minutes, there were a number of operational challenges – notably around quickly collecting data and enabling accurate post breach recovery (PBR).

Since investigations are timebound based on a statement of work (SOW), it became increasingly important to be able to discharge their services whilst providing customers with the best and most valuable information-led insights.

Most investigations utilized several different solutions, and triaging required manual steps and were often limited to a single asset at a time. They needed a flexible solution that could be scheduled to run but also ran ad-hoc so that rapid triage could be performed.

Given time is always critical in a breach, the business acknowledged it needed to work smarter, not harder, by more quickly identifying machines with signs of compromise and IoCs. This model also required high levels of involvement and engagement from their end customers.

Collecting and processing data for a detailed investigation can delay the start, this is exacerbated when you depend on the customer.

CyberClan wanted to lighten the dependency on on their customers, giving them the flexibility to say – we’re here, we’re on it, leave it to us, and we’ll manage all aspects for you. CyberClan needed a solution they could quickly deploy and use to ensure data was collected easily, with support for SFTP, was forensically sound, and not tampered with.

CyberClan wanted to turbocharge the collection of triage data over both offline and remote collection scenarios – alongside looking for ways of speeding up disk imaging efforts – focusing on the evidence that matters first.

They needed to move away from acquisitions taking 8 hours on average and accelerate this to facilitate doing more for their customers, with less involvement.

CyberClan wanted to move beyond the typical time crunch – shifting to increased automation and better prioritization to allow for more investigations per analyst, but their previous patchwork of tools was causing a speed bottleneck, preventing them from taking on more work.

Solution

CyberClan is leveraging Binalyze AIR to help manage its wider Digital Forensics and Incident Response (DFIR) activities, with a specific focus on using AIR in ransomware cases. For the CyberClan team, it’s all about getting as much relevant data as possible whilst preserving that potential evidence.

Andrew Caldwell, DFIR Lead at CyberClan, shared: “It’s been so easy to get up and running with Binalyze AIR, even the agent is quickly deployed onto lots of different endpoints and performs one big slurp (acquisition). I was able to go through this big amount of information and crosscorrelate an entire domain very easily. Then if I identify something of pertinent value, I can go back and perform a full capture. AIR solves a lot of problems but also embraces new approaches to digital forensics. It does require a subtle change of mindset coming from Blackbox forensics. I’m also relatively new to CyberClan, but I’ve been so impressed with Binalyze AIR I’ve actively encouraged former colleagues and peers to go and check it out”.

Monti Sachdeva, DFIR Lead at CyberClan, went on to explain, “I’ve been really impressed with AIR, all the way from our very first tech demo. In practice, it’s helping us with the acquisition, then automatically firing up the Triage component, letting DRONE, AIR’s automated evidence analyzers, give us even more intelligence. The agent is extremely easy to deploy and use for the average user.

By adding AIR to our arsenal, a single analyst can now manage many more investigations individually. It’s very powerful in getting acquisitions from memory, browsers, RAM, logs, and so many more destinations. We’ve just started using the Investigation Hub feature (formerly Consolidated Report), and we already love it. It’s dramatically improving efficiency when you need to investigate hundreds of endpoints at once, and having one unified view for the entire team is really helpful.

The Timeline feature is also proving to be indispensable in our Incident Response activity. This feature, being largely automated, helps save us more time – removing a lot of reliance on slow manual inputting and juggling of old-school Excel spreadsheet documents. AIR is quickly becoming a one-stop shop for us, keeping all activity within one single pane of glass.”

Final Thoughts


Binalyze AIR is such a comprehensive and powerful DFIR platform. It’s supporting both industry veterans and those new analysts coming into the cyber security space.

AIR is spearheading CyberClan’s training of new colleagues on DFIR fundamentals – with its clean and clear user interface and intuitive design harnessing a powerful depth of capabilities.

“Having a categorization factor of artifacts and being able to pivot inwards, beyond your more traditional warnings of something looking suspicious, and giving priority order – it’s just so useful. It helps us work at scale and even feels a bit like an enhanced EDR function”, shared Andrew.

“We’ve recently attracted some new colleagues into CyberClan, and they’ve shared that a big attraction was because we’re already using AIR; that’s a big compliment because there’s an appreciation growing in the industry for the product,” expanded Monti.

Simon Lang, Head of Digital Forensics & Incident Response at CyberClan, concluded “Binalyze AIR’s robust capabilities in IR triage has significantly streamlined our investigative processes.

It’s a super intuitive and powerful analytical platform, enabling us to quickly identify, analyze, and respond to complex cyber threats.”

Reduce Your Incident Response Time

Reduce Your Incident Response Time

From MDR to full-scale Incident Response

Company Overview


Thrive is a leading provider of NextGen managed services, delivering secure, scalable, and innovative solutions to small and mid-sized organizations.

With a dedicated 24/7/365 Security Operations Center (SOC), Thrive offers robust Threat Detection and Response services, including Managed Detection and Response (MDR) and Managed EDR, to ensure continuous protection and visibility.

In addition to proactive monitoring, Thrive supports its customers with tailored incident response and remediation capabilities designed to minimize disruption and accelerate recovery.

From alerts to answers: the missing link in IR

As Thrive’s 24×7 security offerings matured, so did customers’ expectations. Having built strong relationships through its MDR services, Thrive increasingly found that customers wanted more than alerting—they wanted answers. Fast.

Previously, when serious incidents occurred, Thrive’s SOC would escalate and hand off cases to their customer’s third-party DFIR provider. While this approach could get results, often introduced delays and fragmented the customer experience. The Thrive team, who already understood the customer’s environment intimately, had to step aside while an external team started from scratch.

“Our engineers knew the customer environment, their users, their pain points,” said Kevin Landt, VP of Product Management at Thrive. “But once a third-party DFIR provider stepped in, valuable time was lost—and that’s when customers need clarity most.”

Thrive’s SOC leveraged powerful detection tooling like EDR and SIEM platforms to support its MDR services. These tools offered high value in alerting and monitoring, but lacked the forensic depth needed to answer key questions—like how an attacker got in, what they did, and how far they moved. They weren’t designed for evidence collection or deep investigation at scale.

It became clear that Thrive could close that gap. As demand grew, the leadership team quickly realized they needed tooling that could help them own more of the investigation process—faster, and at scale. They explored open-source and commercial platforms, but many came with trade-offs: steep learning curves, slower time to value, and workflows that forced analysts to work in isolation.

Building a faster, smarter response capability

With a clear goal to close the investigation gap and deliver a more seamless experience for customers, Thrive launched its Incident Response Retainer—an add-on service for existing managed customers.

Designed to extend their 24×7 security operations with complete response services powered by Binalyze AIR.

The team uses AIR to collect artifacts, create and assess timelines, identify indicators of compromise, and conduct detailed triage and threat hunting across impacted systems.

AIR’s unified Investigation Hub brings the entire workflow—detection, analysis, and reporting—into a single interface. This has helped Thrive streamline investigations, accelerate time to insight, and elevate the consistency and quality of reporting delivered to customers.

“We’re often able to provide key findings within an hour,” said Clark. “Even with customers who aren’t pre-deployed, we’re usually delivering solid insights within four hours.”

This speed allows Thrive to de-escalate tense situations quickly—often well before third-party DFIR providers, brought in by customers as part of their cyber insurance policies, begin their work.

One of AIR’s standout capabilities is its ability to surface conclusive evidence that enables the team to validate execution, trace attacker movement, and confidently report findings. Thrive also makes extensive use of AIR’s Triage engine to extend investigations—applying custom rules based on threat intelligence and case-specific indicators to hunt across systems and close out any lingering gaps.

“Our findings have stood up to review by third-party forensics teams,” Clark explained. “In some cases—especially when insurers are involved and bring in their own DFIR vendor—those teams have reviewed our collections and chosen to use them rather than start over.”

AIR’s remote shell capability, interACT, is another critical feature. Thrive uses it frequently for post-compromise access, particularly when adversaries have changed credentials or restricted normal access.

It’s become an essential tool for conducting AD audits, executing tools, and regaining visibility in compromised environments. Thrive’s use of AIR has powered successful outcomes across a wide range of incidents, enabling quicker investigations, stronger reporting, and more resilient responses.”

Outcomes: From deep investigations to faster recovery

Binalyze AIR has transformed how Thrive delivers incident response. AIR empowers the team to investigate more thoroughly, respond faster and operate with greater assurance.

For customers, the difference is immediate: faster answers, clearer communication, and reduced downtime. Thrive now delivers key findings within hours of an incident, compressing timelines that previously stretched into days—especially in cases involving external DFIR providers. Clark explained, they’re “not just telling customers there’s a problem—we’re showing them exactly what happened, how it happened, and what to do next.”

That clarity accelerates the path to recovery. AIR helps Thrive move swiftly from investigation to remediation, arming customers with conclusive evidence and structured reports that streamline communication with legal, compliance, and insurance teams. EVP of Security Operations at Thrive, Audy Bautista, shared that they’re “now able to go deep into investigations and, in a short time, get to the point where we’re talking about recovery and remediation.

That’s real value—for the customers and across the business.”

Internally, AIR has also allowed Thrive to scale more efficiently. The success of the IR Retainer has expanded the company’s footprint with existing customers and unlocked new growth opportunities. What started as a capability gap has become one of Thrive’s fastest-growing service lines. “This has been one of our most successful launches,” said Landt. “Our customers remember how we showed up when it mattered most.”

Conclusion

Thrive’s partnership with Binalyze has redefined how incident response is delivered at scale, delivering conclusive analysis and rapid execution to meet the demands of today’s customers.

With AIR embedded in its IR Retainer, Thrive has turned a critical capability gap into a high-growth service line that’s delighting customers and driving business momentum.

“Our team continues to be better prepared, faster, and more effective,” said Bautista.

Reduce Your Incident Response Time

Reduce Your Incident Response Time

Accelerated Impact

Company Overview

Wipro is a global leader in IT, consulting, and business process services, operating in over 50 countries with a workforce exceeding 220,000. Considered one of the select number of Big Tech organizations, the company has a rich history spanning 75 years, with decades in the IT industry.

Wipro provides comprehensive IT solutions across various industries, including delivering top-notch critical incident response and compromise assessment services in cybersecurity. A commitment to excellence and continuous improvement led Wipro to seek out Binalyze’s Investigation and Response Automation Platform, AIR.

Challenges in Cybersecurity Forensics

Wipro offers a wide range of IT security services, ranging from strategic consultation to dealing with active threats. Digital Forensics and Incident Response (DFIR) plays an important role in Wipro’s security provision, especially as cyber threats have grown more aggressive and sophisticated.

David Charbel, Global Head of Next Gen Threat Hunting at Wipro, explains: “We’re seeing more advanced attacks where threat actors are aiming to blend in with daily network activity and go undetected. It’s essential that our customers are confident we can detect and respond to these attacks before they get out of hand.” Against this increasingly hostile threat landscape, the Wipro security team decided to review its capabilities and ensure it could continue to provide high-quality protection for its customers.

One of the biggest priorities was the ability to identify and respond to fastmoving attacks before they could disrupt customer operations or access sensitive data.

“We found that many of our processes were too manual and involved too many different tools,” David explained. “Previously, multiple tools were used to parse manually extracted data like hives, event logs, amcache, and so on. Bringing that into a single pane of glass with Binalyze AIR eliminated the need for multiple parsing workflows.”

“This meant that critical steps like evidence acquisition could be too slow and disjointed. Working with a large number of diverse customer environments, efficiency is a top priority for us.” David continued: “As well as stopping attacks and limiting their damage, we’re also seeing more demand for detailed post-incident forensics. We need to get to the core of why and how threat actors were able to do what they did in the environment, and customers are also under more pressure from regulators to determine how an incident occurred.”

As Wipro sought to enhance its cybersecurity forensics and incident response capabilities and expand their service offerings, the need for a solution that offered faster, more automated evidence acquisition and analysis became clear.

Further, with many organizations tightening their spending, the Wipro team needed to find a solution that would not result in increased costs for customers.

Adopting Binalyze AIR for Enhanced Incident Response

The team was able to move swiftly in bringing in a new solution to address its challenges, and David explains that Binalyze AIR was always their first choice.

AIR is a highly automated investigation and response platform designed to be both extremely fast and easy to use. The platform greatly accelerates investigation processes with its integrated compromise assessment capability, DRONE, capable of analyzing both acquired evidence and live systems.

Findings are available through AIR’s Investigation Hub to give the team a unified, ‘single pane of glass’ approach to investigating their cases.

David further explained: “We’d heard very positive word of mouth about AIR, so once we’d gone through a demonstration and tried it out, it was almost a foregone conclusion.

We are afforded a lot of autonomy as experts in our field, so we were able to make the decision and bring in the best tool for the job quickly.”

Wipro chose Binalyze AIR for its advanced capabilities in remote evidence acquisition and automated analysis to accelerate the team’s investigation and response capabilities.

The selection process was driven by the need to address the inefficiencies and limitations of their existing tools and processes. Binalyze AIR’s ability to quickly and comprehensively collect and analyze over 500 types of evidential artefacts was a game-changer, providing forensic-level visibility with context needed for comprehensive response and hunting.

David noted: “Binalyze AIR stood out because of its ability to handle large volumes of data quickly and accurately. The automation features, especially the timeline and triage, have transformed our approach to threat hunting and incident management.”

Automation was one of the standout capabilities for Wipro as it drastically reduced the need for manual intervention.

Implementing Binalyze AIR allowed the team to conduct rapid and efficient evidence collection remotely, which was previously a significant bottleneck in their process.

Binalyze AIR also enhanced collaboration within Wipro’s cybersecurity team. The tool’s unified interface provided a single point of visibility for all incident data, making it easier for analysts to work together on investigations using the Investigation Hub.

This collaborative environment was crucial for maintaining a high level of efficiency and effectiveness in managing cybersecurity incidents. The platform’s role-based access control ensured team members could collaborate securely and effectively. Finally, Binalyze’s pricing structure and the low-resource nature of AIR meant that the Wipro team could improve its capabilities without any cost or IT resource burden for its customers.

A transformative result

Binalyze AIR has had a powerful impact on the team’s workflows. David highlighted that it now served as one of their primary tools.

He explained: “The efficiency gains from Binalyze AIR have been remarkable. We can perform in-depth analyses and respond to incidents much faster, which has been crucial in maintaining the high standards of cybersecurity incident management our customers need.

The remote evidence acquisition feature alone has saved us countless hours previously spent on manual processes.” One of the most notable outcomes was the dramatic reduction in time required for evidence collection and analysis.

Before Binalyze, evidence acquisition could take 24-48 hours depending on client resources. Now, collection can be completed in just 2-4 hours, or less than an hour for triage for endpoints where Binalyze AIR is already deployed.

This allowed the team to conduct quicker triage and increase caseload capacity. The efficiency gain meant that Wipro could handle a higher volume of incidents without compromising on the quality of their investigations.

“This agility is really essential for us,” David continued. “Cybersecurity is always unpredictable, and almost every week we’re called in to help on an incident with a customer on an emergency basis. We need to be ready to jump into a crisis at any time.”

The decision to integrate Binalyze AIR into Wipro’s cybersecurity infrastructure was further validated by its ability to scale with their needs. As Wipro continues to grow and tackle increasingly sophisticated cyber threats for its customers, Binalyze AIR’s scalable architecture ensures it can maintain a proactive and robust cybersecurity incident management strategy.

David elaborated: “We are servicing a large pool of clients, so scalability is a top priority for us. We’re working on building out more functionality around the API so we can take AIR’s automation to the next level and drive even more efficiency.”

In summary, deploying Binalyze AIR transformed Wipro’s incident response and cybersecurity forensics operations.

The solution provided substantial efficiency gains, enhanced collaboration, and improved response times, all of which contributed to a stronger and more resilient cybersecurity posture for Wipro’s global customers.

By leveraging advanced automation and remote evidence acquisition, Wipro has set a new standard in managing cyber threats and ensuring comprehensive protection for its clients.

Reduce Your Incident Response Time

Reduce Your Incident Response Time

Rapid Remediation

Company Overview


Turkish Airlines is a globally recognised aviation giant with operations in 129 countries, 330 cities and 340 airports. They employ over 40,000 people worldwide. As a member of IATA, Turkish Airlines is integrated with the global aviation network and relies on a complex infrastructure of critical business and supply chain systems. Protecting these systems, individually and collectively, is a top priority for their security team. This requires a thorough and constant cyber assessment across all stakeholders including aircraft and equipment manufacturers, air-traffic control, airports, airlines and all the other components of the aviation supply chain.

In addition to this supply chain complexity, airlines naturally operate in a highly distributed manner with operations in hundreds of different countries and cities. Each individual location has its own IT requirements and infrastructure. Aviation is one of the most distributed industries in the world. The requirement to interface with public and private cloud services further distributes the potential attack surface that must be secured.

A surge in global travel over recent years, combined with digital transformation initiatives and increased connectivity, has delivered many benefits. However, those benefits have come with an increased complexity that poses additional challenges in terms of cybersecurity. The increasing need for integration and automation at the business level necessitates more robust and resilient protection of IT and network infrastructure to ensure business continuity in a highly regulated industry. All security policies must satisfy a high standard and align with safety-first objectives. In response to the complex and challenging environment, Turkish Airlines has invested heavily in cybersecurity. The Turkish Airlines Cyber Defense Center (CDC) continues to build a world-class team of talented security professionals and utilise best-in-class technology solutions including EDR, SIEM and SOAR solutions.

The company also pays close attention to the latest innovations and technological improvements to ensure they maintain a high degree of cybersecurity readiness and constantly expand coverage and capabilities through the early adoption of new security tools. This policy helps to maintain a strong security posture.

Acquiring evidence remotely from global endpoints in minutes.


With operations across 4 continents, investigations involve endpoint assets distributed all over the world. Security operations are carried out from a central CDC located at the global headquarters in Istanbul. Previously, it was extremely time consuming and expensive to travel to the endpoint assets under investigation and collect forensic evidence. This was a key motivation to invest in a DFIR solution like Binalyze AIR to remotely collect evidence from any endpoint in just a few minutes.

“As part of our security operations program, we run regular cybersecurity exercises. In one of the exercises we have done before implementing Binalyze AIR, we tried to investigate suspicious endpoints in Afghanistan. It took us more than a week to bring the endpoints into the CDC for investigation.

During that process we were also dependent on staff on site, who do not have cybersecurity and IT skills, to prepare and pack the devices appropriately enough for us to be able work on them. We have repeated the same cyber security exercise after implementing Binalyze AIR to our infrastructure and it took less than 1 hour to remotely collect evidence from the endpoints in Afghanistan, investigate the incident, do the reporting and close the case. We also had no issues with human errors during the evidence acquisition process, since the whole process was done by Binalyze AIR remotely and automatically.” said Kadir Yıldız, SVP, Turkish Airlines.

Reducing dwell time and speeding up incident response.


The remote and fast evidence acquisition and triage capabilities of Binalyze AIR, in addition to its automation and native integrations with other security systems, helped the Turkish Airlines team accelerate the incident response process by 55%. This also had the effect of reducing the overall dwell time for cyber incidents.

With Binalyze AIR the Turkish Airlines CDC team are able to collaboratively work on the same case from a single pane of glass. Granular role definition and access control ensures that this collaboration is done with appropriate permissions profiles for each individual team member. With Binalyze AIR, average case resolution time dropped from 3 weeks to 1 hour bringing the case backlog under control. The overall efficiency of the incident response team has increased significantly with Binalyze AIR.

“In a distributed environment like Turkish Airlines, it is hard to get the full granular visibility and root cause of incidents at speed and scale. With Binalyze AIR’s remote evidence acquisition and automated triage we can now investigate and close a case under 1 hour. This would normally take more than 3 weeks in the past.” said Kadir Yıldız, SVP, Turkish Airlines.

Reduce Your Incident Response Time

Reduce Your Incident Response Time