You are here: Analyst's functions > Exploring and retrieving evidence from online devices > What you should know about retrieving evidence

What you should know about retrieving evidence

Description

The function shows the File System tree structure of the device where the agent is installed (or several devices if exploring a target File System).

The File System tree structure can be gradually explored, first reading the first level structure (Retrieve default command) and then exploring folders, followed by reading or re-reading the selected folder (Download subtree command).

Once the concerned file is found, it can be downloaded and saved as file evidence (Download file command)

File System components

The structure of each device shows the folders to be explored and those explored:

Example Description

Device root.

Folder not yet explored.

Explored folder.

 

RCS9.3 | User's and Installation Guide | © COPYRIGHT 2013