Data acquisitions
Data acquisitions allow you to acquire data you need from a single running endpoint. Data is requested via data acquisition scripts, which are maintained using the Web UI. When a data acquisition request is made, the xAgent on the selected host endpoint collects the forensic data requested by the data acquisition script.
Data acquisitions can be requested for Windows, macOS, and Linux endpoints. The data that can be requested varies by platform.
See "Requesting a Data Acquisition" in the Endpoint Security (HX) Server User Guide for more information.
File acquisitions
To rapidly review and respond to potential compromises, you can directly acquire files from a host endpoint. File acquisitions are used for static or dynamic analysis of potential or verified compromises, as well as for evidence retention during insider threat investigations. Use file acquisition requests instruct an xAgent to obtain a file from its host endpoint.
File acquisitions can be requested from Windows, macOS, and Linux endpoints.
See "Requesting File Acquisitions" in the Endpoint Security (HX) Server User Guide for more information.
Triage
You can acquire triage collections from hosts using the Web UI. Triage collections provide a snapshot of what occurred on a host endpoint around the time of an alert.
Multiple triages can be requested simultaneously from a host. In addition, you can select multiple hosts and request triage collections from them.
Triages can be performed for Windows and macOS endpoints only. They are not supported for Linux endpoints.
See "Requesting Triage Acquisitions" in the Endpoint Security (HX) Server User Guide for more information.