sysinfo Audit

Prev Next

Collects general information about the endpoint, such as network drives, registration information, and local time.

Note

The sysinfo audit was formerly known as the w32system audit.

Supported Platforms

Windows, macOS, and Linux

Input Parameters

There are no input parameters for the sysinfo audit but you can include or exclude specific system information for your Windows and macOS endpoint only. The sysinfo audit for your Linux endpoint acquires system’s configuration, including name, date and time settings, currently logged in user, network interfaces, and operating system version information only.

The table below describes the system information you can select to include in the sysinfo audit acquired for your Windows or macOS endpoint only. If no audit information is selected, no data is collected for the corresponding operating system.

Audit Information

Description

User Accounts

List of user accounts from the target system.

Disk Listing

List of physical devices that can be acquired as a disk image.

Volume Listing

List of volumes that may be mounted by physical disks.

Registry Hive List

List of registry hives used in a registry listing audit. These include hives that can only be acquired in raw mode.

Prefetch Entries

Evidence of program execution via files in %SystemRoot%\Prefetch.

System Restore Points

Details associated with each restore point on the system.