From endpoint activity to defensible findings

Endpoint & Forensics

Learn how defenders protect endpoints, preserve volatile evidence, and turn host activity into reliable findings. Start with the concepts, explore a focused tool, or build an investigation lab.

3learning routes 2practical tools 5readiness checks
01

Follow the endpoint evidence

Select each stage to see how an examiner moves from a live system to a supported finding.

Stage 1 Define the question and authority

Identify the device, user, time range, investigation question, and authorised actions before touching the endpoint.

Ask: What am I permitted to examine, and what decision must the evidence support?
02

Find your learning path

Choose what you want to achieve. The page will highlight the best place to begin.

Best match Learn the foundations

Understand endpoint telemetry, response, evidence integrity, and investigation principles before choosing a tool.

Endpoint detectionExplore endpoint activity Use Aurora Lite to collect useful Windows telemetry and examine activity that warrants investigation. Learning Guided beginner Try 15 to 25 min Full lab 2 to 3 hours Outcome Collect and review endpoint evidence for suspicious behaviour. Open guide
Digital forensicsInvestigate an endpoint Use Velociraptor to acquire artefacts, hunt across hosts, and preserve investigation context. Learning Guided beginner Try 25 to 35 min Full lab 3 to 5 hours Outcome Produce a traceable endpoint investigation with supported findings. Open guide
03

Build your foundation

Complete these concept guides before collecting evidence from a real endpoint.

04

Choose a tool by task

Start with the question you need to answer, then use the smallest toolset that can answer it.

Best starting point for focused Windows endpoint telemetry Aurora Lite

Generate and review useful Windows endpoint telemetry in a focused lab before moving to fleet-wide collection or deeper forensic acquisition.

Also consider Velociraptor when you need remote artefact collection, repeatable hunts, or investigation across several endpoints.
Explore Aurora Lite
05

Check your investigation readiness

Complete these checks before collecting data, running hunts, or changing an endpoint.

!
Preparation requiredComplete all five safety checks before starting.
Ready to begin? Start with a clear question. Preserve first, collect deliberately, and report only what the evidence supports. Begin with EDR foundations