Evidence Collection

Learn about the available methods to collect evidence.

The following table outlines the available methods to collect evidence from endpoints.

Method

Description

Collect Evidence task

Automatically collect evidence from endpoints in your environment by running the Collect Evidence task.

Incident Response Evidence Collection security playbook

Automatically collect evidence from endpoints in your environment by creating evidence collection playbooks.

Manual evidence collection

Collect evidence from endpoints without an internet connection to support threat investigation and incident response by using the Trend Micro Incident Response Toolkit.