You can locate and download acquired files, triage collections, Agent Diagnostics, and host endpoint data from the Acquisitions page using the Endpoint Security (HX) Web UI.
The Status column on the Acquisitions grid of the Acquisitions page shows the progress of a triage or data acquisition request. The status changes from Requested, to Acquiring, and then to Acquired (when the acquisition is ready to download).
The following table summarizes the acquisition files you can download for each acquisition type.
Acquisition Type | File Type | Description |
|---|---|---|
Files |
| The |
Triages |
| The Endpoint Security (HX) appliance provides a summary of the triage data in the Triage Viewer when potential compromise information is identified in a triage collection. See Reviewing triage collections in the Triage Viewer . You can also process and review the all of the triage data in the Audit Viewer or download the entire triage |
Data |
or .zip | Most data acquisitions produce a downloadable You can also process and review all of the acquired data in the Audit Viewer. See Reviewing forensic data in Audit Viewer . The Full Memory and Full Disk scripts produce a downloadable |
Agent Diagnostics |
| This |
You can download acquired forensic data from the Hosts or Acquisitions pages. Triage acquisition files can also be downloaded from the Triage Summary page.
Analyst, Senior Analyst, Investigator, or Admin access
Downloading forensic data from the Hosts page
Select Hosts in the Endpoint Security (HX) Web UI.
In the list on either tab, click the expand icon (
) next to the host for which you want alert detail information.The host alert details appear.
Locate the acquisition in the Acquisitions grid at the bottom of the page.
Click Download or Download Full Triage. The link name depends on the kind of forensic data acquisition you have selected.
The acquisition file is downloaded to your computer. For information about reviewing forensic data, see Reviewing forensic data .
Downloading forensic data from the Acquisitions page
Select Acquisitions in the Endpoint Security (HX) Web UI.
Optionally, filter the list of acquisitions in the Acquisitions grid by selecting an acquisition type on the Acquisition type menu. You can select File, Triage, Data, or Agent Diagnostics. You can also filter by status of the acquisition and by the user who requested the acquisition.
In the Acquisitions grid, select the line corresponding to the acquisition data you want to download.
Details about the acquisition appear in the Acquisition Detail pane. You can expand these details to review some of the acquisition data in the Acquisition Detail pane.
Click Download or Download full triage in the Acquisition Detail pane. The link name depends on the kind of forensic data acquisition you have selected.
The acquisition file is downloaded to your computer. For information about reviewing forensic data, see Reviewing forensic data .
Downloading a triage from the Triage Summary page
.mans file from the Triage Summary page:Access the Triage Summary page for a triage. For more information, see Accessing the Triage Summary .
Click Download full triage at the top of the Triage Summary page.
The acquisition
.mansfile is downloaded to your computer.Downloaded
.mansfiles can be opened and reviewed using Redline. For more information, read Reviewing forensic data in Redline .