ESXi Collections

AIR supports the following ESXi Evidence and Artifacts

ESXi Evidence List

#

Category

Evidence

Parsed

Investigation Hub

Files Collected

1

System

Yes

Yes

No

2

System

Yes

Yes

No

3

System

Yes

Yes

No

4

System

Yes

Yes

No

5

Network

Yes

Yes

No

6

Network

Yes

Yes

No

7

Network

Yes

Yes

No

8

Network

Yes

Yes

No

9

Network

Yes

Yes

No

10

Network

Yes

Yes

No

11

Network

Yes

Yes

No

12

Network

Yes

Yes

No

13

Network

Yes

Yes

No

14

Storage

Yes

Yes

No

15

Storage

Yes

Yes

No

16

Storage

Yes

Yes

No

17

Storage

Yes

Yes

No

18

Storage

Yes

Yes

No

19

Users

Yes

Yes

No

20

Users

Yes

Yes

No

21

Users

Yes

Yes

No

22

Processes

Yes

Yes

No

23

Files

Yes

Yes

No

24

System

Yes

Yes

No

25

System

Yes

Yes

No

26

System

Yes

Yes

No

27

System

Yes

Yes

No

28

System

Yes

Yes

No

29

System

Yes

Yes

No

30

System

Yes

Yes

No

31

System

Yes

Yes

No

Last updated

Was this helpful?