Learn about the available methods to collect evidence in the Forensics app.
The following table outlines the available methods to collect evidence from endpoints.
Automatically collect evidence from endpoints in your environment by running the Collect
Evidence task.
Automatically collect evidence from endpoints in your environment by creating evidence
collection playbooks.
Collect evidence from endpoints without an internet connection to support threat investigation
and incident response by using the Trend Micro Incident Response Toolkit.