Collect and manage digital evidence to support threat investigation and incident response.
Forensics
Evidence Archive allows you to collect and manage evidence packages from the endpoints in your environment.
The following table outlines the actions available for Evidence Archive.
|
Click Collect Evidence to gather evidence from the endpoints in your environment.
|
Filter endpoints
|
Use the search box and filters to locate specific endpoints.
|
View evidence packages collected from an endpoint
|
Identify an endpoint and click  to display all packages collected from an endpoint.
Evidence Archive displays the following information about evidence packages:
-
Package: Name of the collected evidence package
-
File size: Size of the package
-
Collection: Collection status of the evidence
Collection statuses include:
-
In progress... (  ): Forensicsis processing the evidence.
-
Successful (  ): Forensicsprocessed the evidence.
-
Partially Successful (  ): Forensics could not process some of the evidence types in the package.
-
Unsuccessful (  ): An error or time-out occurred when processing the evidence package.
-
Source: The product or method that uploaded the evidence package to Forensics
-
Collected: The date and time Forensics received the uploaded evidence package
-
Deletion: The date and time that Forensics will delete the package
 |
WARNING
Forensics automatically deletes evidence packages one year after upload.
|
|
Take additional actions
|
Click  and select an additional action:
|