The Forensics Triage feature enables you to create a custom, standalone executable package that collects all of the forensic artifacts in the configuration. Triage supports data collection from both online and offline hosts, on both Windows and macOS platforms.
Go to Create New Configuration.→ → → → and click
Enter configuration details:
Configuration Name—Enter a name that describes the package.
Description—Enter information that is relevant to the configuration package you are creating .
Platform—Select Windows or macOS.
Select artifacts for collection:
Select one of the preconfigured options—Light, Standard or Heavy.
Select any of the artifacts required for the triage collection.
(Optional) Create a new group to collect custom files:
Click Create New Group.
Enter the name of the group.
Enter one or more paths from where to collect the artifacts.
(Optional) Click Add New Group to add additional groups.
Click Create Configuration.