The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Collect forensic data

Prev Next

After performing investigative actions, you need to gather forensic evidence from endpoints to validate suspicious activity and understand its impact. This step focuses on retrieving data such as files, processes, registry entries, and system activity that can support deeper analysis.

The available collection methods include:

  • Using the EDR workspace — Start a collection from dashboards such as Monitoring, Device Search, or Historical Search. This method is alert-driven, and all collected data can be analyzed in the Collections dashboard.

  • Using the Forensics workspace — Run acquisitions on endpoints to retrieve files, registry data, memory snapshots, or system information. This method is host-centric and provides a broader view of endpoint activity that supports deeper investigation. All collected data can be viewed in the Acquisitions page.