GTI forensics connects to the GTI cloud and extracts the forensics information for the endpoint. It displays the threat details for the endpoint.
Navigate to Analysis → <Admin Domain Name> → Attack Log.
Select the alert whose IP address to which you want to perform forensics.
Click Other Actions, and select Perform GTI Forensics. Click the endpoint IP for which you want to perform forensics.
The Threat Intelligence forensics page opens in your browser with information about the endpoint.