Supplied data acquisition scripts

Prev Next

Trellix supplies several data acquisition scripts that you can use to get started with data acquisition requests. You cannot delete these scripts. You can copy and edit some of them to use as a basis for your own scripts. If you have edited them, you can also reset them to their factory-distributed form.

Some of these supplied scripts can be used in a data acquisition request. Most of them produce a downloadable .mans file that can be reviewed in Redline and in the Audit Viewer. The Full Memory script and the Full Disk script produce a downloadable .zip file.

The table below list the supported operating system platforms for each script.

Supplied script name

Endpoint operating system support

Windows

macOS

Linux

Agent Diagnostics

Yes

Yes

Yes

Command Shell History Script

Yes

No

No

Comprehensive Investigative Details Script

Yes

Yes

Yes

Driver Memory Script

Yes

No

No

Full Disk Script

Yes

No

No

Full Memory Script

Yes

No

No

PowerShell History Script

Yes

No

No

Process Details Script

Yes

Yes

No

Process Memory Script

Yes

No

No

Quick File Listing

Yes

Yes

Yes

Standard Investigative Details Script

Yes

Yes

Yes

This section provides a description for each script and instructions for adding and editing comments to your data acquisition requests. For information about any audit modules used by these scripts, see the Endpoint Security (HX) Audit Reference Guide.