Trellix supplies several data acquisition scripts that you can use to get started with data acquisition requests. You cannot delete these scripts. You can copy and edit some of them to use as a basis for your own scripts. If you have edited them, you can also reset them to their factory-distributed form.
Some of these supplied scripts can be used in a data acquisition request. Most of them produce a downloadable .mans file that can be reviewed in Redline and in the Audit Viewer. The Full Memory script and the Full Disk script produce a downloadable .zip file.
The table below list the supported operating system platforms for each script.
Supplied script name | Endpoint operating system support | ||
|---|---|---|---|
Windows | macOS | Linux | |
Agent Diagnostics | Yes | Yes | Yes |
Command Shell History Script | Yes | No | No |
Comprehensive Investigative Details Script | Yes | Yes | Yes |
Yes | No | No | |
Yes | No | No | |
Yes | No | No | |
PowerShell History Script | Yes | No | No |
Process Details Script | Yes | Yes | No |
Yes | No | No | |
Quick File Listing | Yes | Yes | Yes |
Yes | Yes | Yes | |
This section provides a description for each script and instructions for adding and editing comments to your data acquisition requests. For information about any audit modules used by these scripts, see the Endpoint Security (HX) Audit Reference Guide.