After identifying a suspicious file object in your local environment, you can collect the file in a password-protected archive and download the file from Response Management.
The following services can run this task:
-
TrendAI Vision One™
-
Windows agent
-
Linux agent
-
macOS agent
-
-
Apex One as a Service
-
Windows agent
-
-
Cloud One - Endpoint & Workload Security
-
Windows agent
-
Linux agent
-
macOS agent
-
-
Deep Discovery Inspector
-
Virtual Network Sensor
WARNINGDownloading suspicious samples may potentially harm your endpoint. Take necessary
precautions before continuing. TrendAI Vision One™ automatically stores the collected samples in a password-protected .zip archive.
|
Procedure
- Right-click the suspicious file you want to collect, and select Collect File from the drop-down menu.The Collect File Task screen appears.

Note
-
This task does not support collection of files larger than 4 GB, protected Windows files, and UNC paths for file objects.
-
The maximum file size for this task depends on the agent version installed on the target endpoint:OSAgent versionMaximum file sizeLinuxBefore 20.0.2.29760128 MB20.0.2.29760 and later4 GBWindowsBefore 20.0.2.29760128 MB20.0.2.29760 and later4 GB
-
- Specify a Description for the response or event.
- Click Create.TrendAI Vision One™ creates the task and displays the current task status in Response Management.
- Monitor the task status.
- Go to .
- Locate the task using the search bar or by selecting Collect File from the Action drop-down list.
- View the task status.
-
Pending approval (
): The automated response task was created in Workbench and is waiting for approval. -
Rejected (
): The automated response task created in Workbench was rejected. -
In progress (
): TrendAI Vision One™ sent the command
and is waiting for a response. -
Queued (
): The managing server queued the
command because the agent was offline. -
Successful (
): The command was successfully
executed. -
Unsuccessful (
): An error or time-out occurred when attempting to send
the command to the managing server, the Security Agent is offline for more than 12
hours, or the command execution timed out.
-
- Download the sample file.
- In Response Management, find the Collect File task and click the options button (
) at the right of the row. - Click Download File.
- On the screen that appears, record the password for the archived sample.
- Click OK to download the file.

WARNING
Downloading suspicious samples may potentially harm your endpoint. Take necessary precautions before continuing. TrendAI Vision One™ automatically stores the collected samples in a password-protected .zip archive.Use a file archiver to extract and decompress the file contents.
- In Response Management, find the Collect File task and click the options button (
