File

Prev Next

The File script requests a list of files using system calls from your host endpoints. This script can be requested for Windows endpoints only.

Note

File script support is not provided for macOS or Linux host endpoints.

You cannot copy, edit, reset, import, or delete the Quick File Listing script or use this script in data acquisition scripts you create. This script does not appear on the Data Acquisition Scripts page.

HX_SSType_File_scap.png

The following table describes the fields in this dialog box. Use the default values or enter new values.

Field

Description

Filename

(Required) Specify the name of the data acquisition file to acquire.

Path

Specify the global path or the symbolic link to the disk or volume from which you want to acquire the list of files using system calls.

Using

Raw

Gathers a list of files by directly examining the structures on the target system's disks.

API

Comment

Enter details about your specific data acquisition request and enter the reason you want to acquire the file.

Note

The Quick File Listing dialog box also shows the percentage of allotted disk space currently used to store acquisitions and how much free disk space (in GB) remains.

Requesting File Data

To request file data using the Web UI:
  1. Select Hosts in the Endpoint Security (HX) Web UI.

  2. Select one or more hosts.

  3. From the Actions menu, select File. Alternatively, you can select File from the Acquire menu on a host details page.

  4. Click Go to access the File dialog box.

  5. Enter the filename in the Filename field.

  6. Enter the file path in the Path field.

  7. Select the type of file acquisition you want to retrieve from you host endpoint. Options include Raw and API.

  8. In the Comment field, enter the reason you want to acquire the file listing and any details about the data acquisition request that you want to track.

  9. Click Acquire.