Collect evidence to support threat investigation and incident response.
After adding endpoints to a workspace in the Forensics and Analysis app, you can collect evidence using context menus in the Trend Vision One console.
Evidence collection requires that you enable XDR endpoint sensor on target endpoints.
Evidence archives use the same folder structures as the SANS Institutes and CyLR tool.
Trend Vision One creates the task and displays the current command status on the Response Management app.
In progress... (): Trend Vision One sent the command
to the managing server and is waiting for a response
Queued (): The managing server queued the command because the agent was offline
Successful (): The managing server successfully received
the command
Unsuccessful (): An error or time-out occurred when attempting to send the command to the managing server, the agent is offline for more than 24 hours, or the command execution timed out