The Forensics workspace supports acquisitions that are initiated directly from endpoints. From the Acquisitions page, you can collect files, registry data, memory snapshots, and system information to build a comprehensive view of endpoint activity. The collected data is accessible from the Acquisitions page for review and analysis.
Collect forensic data from the Forensics workspace
- Published on Aug 26, 2026
- 1 minute(s) read
Was this article helpful?