Import Offline Triage - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR Pro Administrator Guide

Product
Cortex XDR
License
Pro
Creation date
2023-10-31
Last date published
2024-03-27
Category
Administrator Guide
Abstract

Use the import offline triage to upload archives containing forensic data collected by the offline collector.

Use the Import Offline Triage to upload archives containing forensic data collected by the Offline Collector. After the archive has been uploaded, the data is extracted and ingested into the Forensics tables on the tenant. Import Offline Triage supports uploading packages created on both the Windows and macOS platforms..

  1. Go to ForensicsTriageConfiguration+Import Offline Triage.

  2. Drag and drop or use the browse link to search for the file.

    Note

    More than one offline triage package can be uploaded at a time.

  3. Click Done.

  4. Go to ForensicsTriageTriage All to check the status of the file/s.