Collect evidence to support threat investigation and incident response.
This task is supported by the following services:
-
Trend Vision One
-
Windows agent
-
After creating a workspace and adding endpoints to the workspace in the
Forensics app, you can collect
detailed evidence from potentially compromised endpoints for internal investigations
into critical incidents that occurred on your network and may require further
attention.
Important
|
Procedure
- In the Trend Vision One console, go to .
- Click the name of the workspace that has the endpoints you want to triage.
Note
This task automatically adds all collected evidence to the workspace. - Collect evidence from the desired endpoints.
- Select one or more endpoints.
- Click Collect Evidence.
- Specify the evidence types you want to collect.
- Specify a Description for the response or event.
- Click Create.Trend Vision One creates the task and displays the current task status in Response Management.
- Monitor the task status.
- Open Response Management.
- (Optional) Locate the task using the Search field or by selecting Collect Evidence from the Action dropdown list.
- View the task status.
-
In progress (): Trend Vision One sent the command and is waiting for a response.
-
Queued (): The managing server queued the command because the agent was offline.
-
Successful (): The command was successfully executed.
-
Unsuccessful (): An error or time-out occurred when attempting to send the command to the managing server, the agent is offline for more than 24 hours, or the command execution timed out.
-