From endpoint activity to defensible findings

Endpoint & Forensics

Learn how defenders protect endpoints, preserve volatile evidence, and turn host activity into reliable findings. Start with the concepts, explore a focused tool, or build an investigation lab.

3learning routes 2practical tools 5readiness checks
01

Follow the endpoint evidence

Select each stage to see how an examiner moves from a live system to a supported finding.

Stage 1 Define the question and authority

Identify the device, user, time range, investigation question, and authorised actions before touching the endpoint.

Ask: What am I permitted to examine, and what decision must the evidence support?
02

Find your learning path

Choose what you want to achieve. The page will highlight the best place to begin.

Best match Learn the foundations

Understand endpoint telemetry, response, evidence integrity, and investigation principles before choosing a tool.

03

Build your foundation

Complete these concept guides before collecting evidence from a real endpoint.

04

Choose a tool by task

Start with the question you need to answer, then use the smallest toolset that can answer it.

Best starting point for focused Windows endpoint telemetry Aurora Lite

Generate and review useful Windows endpoint telemetry in a focused lab before moving to fleet-wide collection or deeper forensic acquisition.

Also consider Velociraptor when you need remote artefact collection, repeatable hunts, or investigation across several endpoints.
Explore Aurora Lite
05

Check your investigation readiness

Complete these checks before collecting data, running hunts, or changing an endpoint.

!
Preparation requiredComplete all five safety checks before starting.
Ready to begin? Start with a clear question. Preserve first, collect deliberately, and report only what the evidence supports. Begin with EDR foundations