Collect and manage digital evidence to support threat investigation and incident response.
The Evidence Archive tab of Forensics allows you to collect and manage evidence packages from the endpoints in your environment.
The following table outlines the actions available on the Evidence Archive tab.
Action
|
Description
|
||
Click Collect Evidence to collect evidence from the endpoints in your environment.
|
|||
Filter endpoints
|
Use the search field and drop-down list to locate specific endpoints.
|
||
View evidence packages collected from an endpoint
|
Identify an endpoint and click the right arrow () at the
beginning of the row to display all packages collected from an endpoint.
The Evidence Archive tab displays the following information about evidence packages:
|
||
Take additional actions
|
Click the options button () at the end of the row and choose to take additional actions on the evidence package:
|