Evidence

Note: The XDR Forensics feature requires Cisco XDR Advantage or Cisco XDR Premier licensing tier.

The Evidence page in incident detail allows you to acquire and view forensic data from assets within an incident and connect to the assets using a remote shell for remediation purposes. The data varies based on the asset and the acquired data can be used for further analysis and investigation in the XDR Forensics UI. For more information, see XDR Forensics.

Incident evidence details showing 13 forensic acquisition and interactive shell items with their status.