Standard Investigative Details script

Prev Next

The Standard Investigative Details script collects the most common forensic data from host endpoints. You can copy, edit, reset, and export this script on the Data Acquisitions Script page.

This script can be requested for Windows, macOS, and Linux host endpoints.

HX_SSType_StandardInvestigative_scap.png

Requesting standard investigative details

To request standard investigative details using the Web UI:
  1. Select Hosts in the Endpoint Security (HX) Web UI.

  2. Select one or more hosts.

  3. From the Actions menu, select Standard Investigative Details. Alternatively, you can select Standard Investigative Details from the Acquire menu on a host details page.

  4. Click Go to access the Acquire Standard Investigative Details dialog box.

  5. In the Comment field, enter the reason you want to acquire the file and any details about the data acquisition request that you want to track.

  6. Click Acquire.

The Acquire Standard Investigative Details dialog box also shows the percentage of allotted disk space currently used to store acquisitions and how much free disk space (in GB) remains.

Agent Diagnostics data can be requested as a regular data acquisition. See Requesting a data acquisition.