Windows
Process lists, Prefetch, event logs and autoruns help you examine execution and persistence.
Example artifactWindows.Forensics.PrefetchDigital Forensics brings endpoint collection, forensic search and timeline review into one investigation workflow. Gather the relevant artifacts, inspect their source records and give your team a clearer basis for deciding what happened.
Was this process expected on this endpoint?
Open a record to inspect its source artifact and fields. Classification helps organize the evidence; an analyst still needs to assess what it means.
Synthetic records. Indexed times can differ from original event times. This sequence illustrates the workflow, not collection speed or a confirmed attack.Choose an endpoint and select artifacts appropriate to its operating system. Process lists and network connections show current activity; execution history, persistence and logs add context. Available artifacts depend on the endpoint and its configured collector.
Process lists, Prefetch, event logs and autoruns help you examine execution and persistence.
Example artifactWindows.Forensics.PrefetchProcesses, launch agents and filesystem events help you inspect activity on a Mac.
Example artifactMacOS.Forensics.FSEventsProcesses, SSH login records, cron jobs and shell history provide endpoint context.
Example artifactLinux.Syslog.SSHLoginHunts run a selected artifact across a target group, with include and exclude labels and an expiry. Review results as endpoints respond.
Collection requires an available Endpoint Agent Server and the relevant permissions. A returned collection does not guarantee every result was indexed; check that the records you need are available.
Search by endpoint, artifact and time window. Use the timeline’s event density and category lanes to narrow the review, then open an event’s source fields and raw record. The evidence stays close to the question you are investigating.
Find relevant terms and fields in indexed artifacts. Narrow large result sets so the records you need are in view.
Brush a time window and inspect event categories, including Process, Network, File System and Persistence. Select a record for its details.
Read the artifact name, endpoint and key fields. Compare original timestamps before drawing conclusions about the sequence or time spent inside.
A clearer basis for the next decision.
Work back from an event to its supporting fields, instead of treating a category or severity label as a verdict.
Digital Forensics is part of SecOps Platform. Separate permissions govern search, timeline access, collection and response actions, so access to evidence does not automatically grant permission to change an endpoint.
The AI Assistant’s hunt mode can query forensic data, retrieve timelines and work with hunts. Tool availability follows the mode; high-risk tools require approval before execution.
When a collection or download action includes case context, its audit record carries the case reference, actor and target. That links forensic work to the wider investigation.
Review collection failures, missing records and source timestamps. A timeline supports your assessment; it does not itself establish root cause or a complete chain of custody.
No. Start with a selected endpoint and the artifacts relevant to your question. Search can also use records already indexed. A hunt extends a selected collection to a group of endpoints.
No. Windows, macOS and Linux have different artifact selections. The collector must support the chosen artifact, and the endpoint must be accessible for collection.
It helps you examine indexed evidence in time order. Some timestamps reflect ingestion rather than the original event. Check the source record and corroborate the sequence before concluding root cause or dwell time.
Use a deployment with SecOps Platform access, configure the Endpoint Agent Server and enroll the endpoints you intend to investigate. Assign the required permissions, collect a small artifact set, and verify it is searchable before expanding the scope.
Have any other questions? Talk to our team
See how endpoint collection, forensic search and timeline review fit your investigation workflow.