Skip to content
Explore platformDigital Forensics
Digital Forensics

Reconstruct the incident.
Keep the evidence in view.

Digital Forensics brings endpoint collection, forensic search and timeline review into one investigation workflow. Gather the relevant artifacts, inspect their source records and give your team a clearer basis for deciding what happened.

OS-specific collectionSearchable evidenceTimeline & source detail
Forensic InvestigationIllustrative workflow
01ScopeChoose an endpoint
02CollectSelect artifacts
03SearchReview indexed records
04InspectOpen source details
LAB-WS-07 · WindowsSearch / Indices / Timeline
Collected evidenceIndexed time
One endpoint. Different artifact types.
Inspect a record to follow its source.
Event detailProcess
PowerShell process
Source Artifact
Windows.System.Pslist
Hostname
LAB-WS-07
Parent process
WmiPrvSE.exe
Process start · source field
09:41:07
Analyst’s next question

Was this process expected on this endpoint?

Open a record to inspect its source artifact and fields. Classification helps organize the evidence; an analyst still needs to assess what it means.

Synthetic records. Indexed times can differ from original event times. This sequence illustrates the workflow, not collection speed or a confirmed attack.
01 - Collection

Collect what the investigation needs.

Choose an endpoint and select artifacts appropriate to its operating system. Process lists and network connections show current activity; execution history, persistence and logs add context. Available artifacts depend on the endpoint and its configured collector.

Windows

Process lists, Prefetch, event logs and autoruns help you examine execution and persistence.

Example artifactWindows.Forensics.Prefetch

macOS

Processes, launch agents and filesystem events help you inspect activity on a Mac.

Example artifactMacOS.Forensics.FSEvents

Linux

Processes, SSH login records, cron jobs and shell history provide endpoint context.

Example artifactLinux.Syslog.SSHLogin
Widen the scope deliberately.

Hunts run a selected artifact across a target group, with include and exclude labels and an expiry. Review results as endpoints respond.

Collection requires an available Endpoint Agent Server and the relevant permissions. A returned collection does not guarantee every result was indexed; check that the records you need are available.

02 - Reconstruction

Move from a pattern to the record behind it.

Search by endpoint, artifact and time window. Use the timeline’s event density and category lanes to narrow the review, then open an event’s source fields and raw record. The evidence stays close to the question you are investigating.

Three views of the same investigationForensic workspace

Search the evidence

Find relevant terms and fields in indexed artifacts. Narrow large result sets so the records you need are in view.

Focus the timeline

Brush a time window and inspect event categories, including Process, Network, File System and Persistence. Select a record for its details.

Check the source

Read the artifact name, endpoint and key fields. Compare original timestamps before drawing conclusions about the sequence or time spent inside.

A clearer basis for the next decision.
Work back from an event to its supporting fields, instead of treating a category or severity label as a verdict.

03 - Investigation & control

Keep investigation work accountable.

Digital Forensics is part of SecOps Platform. Separate permissions govern search, timeline access, collection and response actions, so access to evidence does not automatically grant permission to change an endpoint.

Ask for a focused hunt.

The AI Assistant’s hunt mode can query forensic data, retrieve timelines and work with hunts. Tool availability follows the mode; high-risk tools require approval before execution.

Connect actions to a case.

When a collection or download action includes case context, its audit record carries the case reference, actor and target. That links forensic work to the wider investigation.

Verify before concluding.

Review collection failures, missing records and source timestamps. A timeline supports your assessment; it does not itself establish root cause or a complete chain of custody.

Questions about Digital Forensics.

1Do we need to collect everything first?

No. Start with a selected endpoint and the artifacts relevant to your question. Search can also use records already indexed. A hunt extends a selected collection to a group of endpoints.

2Are the same artifacts available on every operating system?

No. Windows, macOS and Linux have different artifact selections. The collector must support the chosen artifact, and the endpoint must be accessible for collection.

3Does the timeline prove when an attack started?

It helps you examine indexed evidence in time order. Some timestamps reflect ingestion rather than the original event. Check the source record and corroborate the sequence before concluding root cause or dwell time.

4How do we start?

Use a deployment with SecOps Platform access, configure the Endpoint Agent Server and enroll the endpoints you intend to investigate. Assign the required permissions, collect a small artifact set, and verify it is searchable before expanding the scope.

Have any other questions? Talk to our team

Bring an incident.Follow the evidence.

See how endpoint collection, forensic search and timeline review fit your investigation workflow.