The Command Shell History script requests a command shell history from host endpoints. This script can be requested only for Windows host endpoints. Support is not provided for macOS or Linux host endpoints.
This script cannot be copied, edited, reset, or deleted and does not appear on the Data Acquisition Scripts page. You cannot use this script in data acquisition scripts that you create.
.png)
Requesting command shell history data
Select Hosts in the Endpoint Security (HX) Web UI.
Select one or more hosts.
From the Actions menu, select Command Shell History. Alternatively, you can also select Command Shell History from the Acquire menu on a host details page.
Click Go to access the Acquire Command Shell History dialog box.
In the Comment field, enter the reason you want to acquire the file and any details about the data acquisition request that you want to track.
Click Acquire.
The Acquire Command Shell History dialog box also shows the percentage of allotted disk space currently used to store acquisitions and how much free disk space (in GB) remains.
Command Shell History data can be requested as a regular data acquisition. See Requesting a data acquisition.