Investigation
The Investigation API provides the following methods to perform various threat investigation actions:
collectInvestigationPackage: initiates a forensic collection task on an endpoint.getInvestigationFileUrl: returns the current status and outcome of a task started viacollectInvestigationPackage.killProcess: terminates a running process on a managed endpoint.
API URL: CONTROL_CENTER_APIs_ACCESS_URL/v1.0/jsonrpc/investigation.
Important
These methods require:
A license that includes EDR for the company to which the target endpoint belongs.
Advanced Investigation and Manage Networks rights.