Collect forensic data from the Forensics workspace

Prev Next

The Forensics workspace supports acquisitions that are initiated directly from endpoints. From the Acquisitions page, you can collect files, registry data, memory snapshots, and system information to build a comprehensive view of endpoint activity. The collected data is accessible from the Acquisitions page for review and analysis.