What you should know about retrieving evidence

Description

The function shows the FileSystem tree structure of the device where the agent is installed (or several devices if exploring a target FileSystem).

The FileSystem tree structure can be gradually explored, first reading the first level structure (Retrieve default command) and then exploring folders, followed by reading or re-reading the selected folder (Retrieve subtree command).

Once the concerned file is found, it can be downloaded and saved as file evidence (Download command)

NOTE: a folder is read or a file is downloaded after synchronization.

File System components

The structure of each device shows the folders to be explored and those explored:

Example Description

Device root.

Folder not yet explored.

Explored folder.