Endpoint & Forensics
Learn how defenders protect endpoints, preserve volatile evidence, and turn host activity into reliable findings. Start with the concepts, explore a focused tool, or build an investigation lab.
Follow the endpoint evidence
Select each stage to see how an examiner moves from a live system to a supported finding.
Identify the device, user, time range, investigation question, and authorised actions before touching the endpoint.
Ask: What am I permitted to examine, and what decision must the evidence support?Find your learning path
Choose what you want to achieve. The page will highlight the best place to begin.
Understand endpoint telemetry, response, evidence integrity, and investigation principles before choosing a tool.
Build your foundation
Complete these concept guides before collecting evidence from a real endpoint.
Choose a tool by task
Start with the question you need to answer, then use the smallest toolset that can answer it.
Generate and review useful Windows endpoint telemetry in a focused lab before moving to fleet-wide collection or deeper forensic acquisition.
Check your investigation readiness
Complete these checks before collecting data, running hunts, or changing an endpoint.