Collect forensic data

Prev Next

After performing investigative actions, you need to gather forensic evidence from endpoints to validate suspicious activity and understand its impact. This step focuses on retrieving data such as files, processes, registry entries, and system activity that can support deeper analysis.

The available collection methods include:

  • Using the EDR workspace — Start a collection from dashboards such as Monitoring, Device Search, or Historical Search. This method is alert-driven, and all collected data can be analyzed in the Collections dashboard.

  • Using the Forensics workspace — Run acquisitions on endpoints to retrieve files, registry data, memory snapshots, or system information. This method is host-centric and provides a broader view of endpoint activity that supports deeper investigation. All collected data can be viewed in the Acquisitions page.