When a Endpoint Security (HX) user requests a file, the appliance obtains the file from the host endpoint. Use file acquisitions for static analysis, dynamic analysis, or evidence retention. The system collects acquisition information in a .zip file.
Each acquisition request can only obtain one file at a time from an individual host endpoint. You can request the same file from multiple host endpoints using host sets. You can request other files from the same host endpoint by making additional requests. The only limits on the total number of acquisition requests you can make for any host endpoint are related to acquisition aging settings.
You can control the following file acquisition functions using file acquisition settings:
Function | Description |
|---|---|
Enable or disable file acquisitions | Enables file acquisitions. File acquisitions are enabled by default. |
Specify the file acquisition passphrase | Identifies the passphrase used to encrypt file acquisition. See Changing the file acquisition passphrase using the CLI . |
Admin access