Collect forensic data using the EDR workspace

Prev Next

The EDR workspace supports collections that are initiated in response to alerts or search results. From the Monitoring, Device Search, or Historical Search dashboards, you can collect files, process details, registry entries, and other endpoint artifacts associated with suspicious activity. The collected data can be accessed from the Collections dashboard for review and analysis.