Patent attributes
Techniques are described for performing forensic assisting and tracing of transaction data from an automated teller machine (ATM) to detect suspicious activity and potential security threats. The techniques include a forensic assisting and tracing (FAST) ATM configured to intercept data packets including transaction data generated by the ATM; map, store, and index the transaction data; and analyze metadata for the transaction data to generate reports on the operation of the ATM for a higher-level hub server. In some examples, a plurality of FAST ATMs may be networked to the hub server such that the hub server receives reports from each of the individual FAST ATMs and analyzes the reports to identify larger, global trends of suspicious activity and potential security threats.