The following table describes different types of evidence supported by the Incident Response Evidence Collection playbook, Collect Evidence task, and Trend Micro Incident Response Toolkit.
Evidence Type |
Description |
---|---|
Basic information |
|
Account information |
Accounts on this endpoint, including
|
Network information |
Network-related tables and configuration, including
|
System execution information |
Executed process records, including
|
Event log |
Windows Event Log, including
|
Registry |
Endpoint registry hive |
User activity |
Endpoint user behavior log, including
|
File timeline |
Endpoint file system information, including the Master File Table (MFT) |
Process information |
Live processes currently running on endpoint |
Service information |
Applications executed in the foreground background, including
|