This section describes two investigation modules that provide targeted forensic data analysis. Process Tracker traces process execution chains to identify suspicious parent–child relationships and unusual propagation activity. Logon Tracker reconstructs authentication events to determine account usage patterns and possible lateral movement. These modules operate within the investigation workflow and use data collected from endpoint snapshots, searches, and integrated sources. They enable you to correlate events, validate findings, and establish the scope of compromise before proceeding to remediation.
Analyze forensic data using HX modules
- Published on Aug 26, 2026
- 1 minute(s) read
Was this article helpful?