Comprehensive Investigative Details script

Prev Next

The Comprehensive Investigative Details script collects more comprehensive forensic data from host endpoints than the Standard Investigative Details script. All but the most prohibitively expensive investigative data is collected. This script can be requested for Windows, macOS, and Linux host endpoints.

You can copy, edit, reset, and export this script on the Data Acquisitions script page.

HX_SSType_ComprehensiveInvestigative_scap.png

Requesting comprehensive investigative details

To acquire comprehensive investigative details using the Web UI:
  1. Select Hosts in the Endpoint Security (HX) Web UI.

  2. Select one or more hosts.

  3. From the Actions menu, select Comprehensive Investigative Details. Alternatively, you can select Comprehensive Investigative Details from the Acquire menu on a host details page.

  4. Click Go to access the Acquire Comprehensive Investigative Details dialog box.

  5. In the Comment field, enter the reason you want to acquire the file and log details about the data acquisition request that you want to track.

  6. Click Acquire.

The Acquire Comprehensive Investigative Details dialog box also shows the percentage of allotted disk space currently used to store acquisitions and how much free disk space (in GB) remains.

Comprehensive Investigative Details can be requested as a regular data acquisition. See Requesting a data acquisition.