Organize and analyze the collected evidence by using workspaces.
This feature is not available in all regions.
The following table outlines the actions available for workspaces.
Action |
Description |
---|---|
Add endpoints to workspace |
Click Add Endpoints to add endpoints from Endpoint Inventory. Note:
The Forensics and Analysis only supports windows platforms. |
Find an endpoint name, click the options icon ( Note:
Evidence is automatically added to the workspace after collection. |
|
Add packages to workspace |
Click Add Packages to add evidence packages from the Packages tab. |
View collected evidence |
Find an evidence package, click the options icon ( |
Create an investigation timeline with the collected evidence to gain insight into the context of an incident. |