Streamline Data Collection and Analysis
To resolve an incident, you need to find the entry point and track down remnants even if adversaries tried to cover their tracks. The Cortex XDR Forensic module, integrated into the Cortex XDR agent, gathers comprehensive data and displays investigative details in an intuitive forensics workbench.
Rich forensics evidence:
Instantly access a wealth of artifacts, including event logs, registry keys, browser history, process execution, drives, command history and more.
Offline data collection:
Download a complete forensics snapshot of an air-gapped endpoint, upload it to Cortex XDR, and analyze it together with other forensics data.