File acquisitions

Prev Next

To review and respond rapidly to potential compromises, you can directly acquire files from a host endpoint. File acquisitions are used for static or dynamic analysis of potential or verified compromises, as well as for evidence retention during insider threat investigations. Use file acquisition requests to instruct an agent to obtain a file from its host endpoint.

File acquisitions can be requested from Windows, macOS, and Linux endpoints.

See Requesting file acquisitions for more information.