Workspaces

Organize and analyze the collected evidence by using workspaces.

Important:

This feature is not available in all regions.

The following table outlines the actions available for workspaces.

Action

Description

Add endpoints to workspace

Click Add Endpoints to add endpoints from Endpoint Inventory.

Note:

The Forensics and Analysis only supports windows platforms.

Collect evidence from endpoint

Find an endpoint name, click the options icon () at the end of the row, and click Collect Evidence to collect evidence from the endpoint.

Note:

Evidence is automatically added to the workspace after collection.

Add packages to workspace

Click Add Packages to add evidence packages from the Packages tab.

View collected evidence

Find an evidence package, click the options icon () at the end of the row, and click View Evidence Report to see the contents of the evidence package.

Create an investigation timeline

Create an investigation timeline with the collected evidence to gain insight into the context of an incident.