Supported Evidence

These pages categorize the supported evidence and artifacts by OS, indicating whether each item is parsed and presented in the Investigation Hub and/or if the associated file is collected.

https://github.com/binalyze-kb/temp/blob/main/usdproduct/features/acquisition/supported-evidence/windows-collections/README.mdmacOS CollectionsLinux CollectionsIBM AIX Collections

Collection Type:

File Count

Windows artifact

119

Windows evidence

191

macOS artifact

27

macOS evidence

175

Linux artifact

25

Linux evidence

135

AIX artifact

7

AIX evidence

19

Grand Total

698

Last updated

Was this helpful?