File acquisition requests instruct theEDRF Client to obtain a file from its host endpoint. File acquisitions are used for static or dynamic analysis of potential or verified compromises, as well as for evidence retention during insider threat investigations.
Authorized users can request a file acquisition. See Requesting file acquisitions . The resulting downloadable .zip file is lightly encrypted with a passphrase.
Note
Changing the passphrase does not improve security. The passphrase prevents antivirus software from flagging the package as malicious when downloaded. Acquisition packages may contain malicious content.
Each acquisition request can only obtain one file at a time from an individual host endpoint. You can request the same file from multiple host endpoints by using host sets. You can request other files from the same host endpoint by making additional requests. The only limits on the total number of acquisition requests you can make for any host endpoint are related to acquisition aging settings.
Important
The Endpoint Security (HX) appliance cannot list or acquire files from network-mounted shares. If you try to list or acquire such files, an error will occur.
In addition, file acquisitions may not be performed for temporary files.