collection

EDRs don’t collect all DFIR artifacts,
but they can help you do it

Start Reading

Collect Arbitrary Files Any Time During Incident Response

Start Reading