Collect evidence from endpoints without an internet connection to support threat investigation and incident response by using the Trend Micro Incident Response Toolkit.
Evidence archives use the same folder structures as the SANS Institutes and CyLR tool.
This feature is not available in all regions.
./TMIRT-0.5.0.1007.exe evidence --task_id <file prefix> <evidence type> --data_output_folder <location>
The following table outlines the available arguments to execute the toolkit.
Argument |
Description |
---|---|
<file prefix> |
Name prefix for the package the toolkit generates. |
<evidence type> |
Evidence types the toolkit can collect. Include at least one separated by spaces. Available evidence types:
|
<location> |
Directory where the toolkit stores the zip file with the collected evidence. |
The Forensics and Analysis app begins processing the uploaded package.
Processing evidence packages can take up to 30 minutes.
Do not close the browser tab or refresh the screen until the process finishes.