Skip to main content

Investigation

The Investigation API provides the following methods to perform various threat investigation actions:

  • collectInvestigationPackage: initiates a forensic collection task on an endpoint.

  • getInvestigationFileUrl: returns the current status and outcome of a task started via collectInvestigationPackage.

  • killProcess: terminates a running process on a managed endpoint.

API URL: CONTROL_CENTER_APIs_ACCESS_URL/v1.0/jsonrpc/investigation.

Important

These methods require:

  • A license that includes EDR for the company to which the target endpoint belongs.

  • Advanced Investigation and Manage Networks rights.