The EDR workspace supports collections that are initiated in response to alerts or search results. From the Monitoring, Device Search, or Historical Search dashboards, you can collect files, process details, registry entries, and other endpoint artifacts associated with suspicious activity. The collected data can be accessed from the Collections dashboard for review and analysis.
Collect forensic data using the EDR workspace
- Published on Aug 26, 2026
- 1 minute(s) read
Was this article helpful?