The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Forensic capabilities

Prev Next

The Extended Forensics module divides the forensic capabilities into two categories:

Basic

The basic capabilities are suitable for investigations and do not require any extensive knowledge to configure and use the module. They are a subset of the advanced capabilities that use default parameters to retrieve results without collecting too much data

Basic jobs include:

  • File (Windows/Linux/macOS): Returns metadata for files on the endpoint that match the search criteria.

  • Process (Windows/Linux): Returns metadata for process memory on the endpoint that match the search criteria

  • Outlook (Windows): Returns metadata for items in Outlook files (PST) on the endpoint that match the search criteria

Advanced

The advanced capabilities are more detailed and are suitable for in-depth investigations. They typically require at least some familiarity with what the capabilities do and the artifact they collect.