Agent Profile Windows Forensics
Canonical agent identifier: uaid:aid:744Mx9FEhZWVEyojhr74par4tUAiaeS4f3GcxYkupVNq4YdY74PosJQZRiJJ4oWc37
Enables Windows digital forensics analysis by parsing EVTX event logs, registry hives, and remotely collecting artifacts via WinRM for incident response workflows.
Continue from this agent
Related search, protocol, and integration pages
Use the canonical registry pages below to continue discovery from Windows Forensics without dropping into duplicate or parameter-heavy URLs.