AIR icon

AIR

Manage Binalyze AIR resources

Acquisition → Assign Evidence Acquisition Task

AI-generated

Overview

This node operation assigns an evidence acquisition task within the Binalyze AIR platform. It is used to initiate and manage remote acquisition tasks on endpoints, specifying details such as the organization, case, acquisition profile, and storage location for the evidence. This operation is beneficial for digital forensics and incident response teams who need to automate and streamline the collection of forensic evidence from multiple endpoints.

Use Case Examples

  1. Assign an acquisition task to a specific case within an organization using a predefined acquisition profile, saving the evidence locally or to a repository.
  2. Filter endpoints by asset name, IP address, platform, or tags to target specific devices for evidence acquisition.

Properties

Name Meaning
Organization The organization for the acquisition task, selectable by list, ID, or name.
Case The case to assign the acquisition task to, selectable by list or ID.
Acquisition Profile The acquisition profile to use for the task, selectable by list or ID.
Task Name Optional name for the acquisition task.
Save To Where to save the acquired evidence, either locally or to a configured evidence repository.
Evidence Repository The evidence repository to save the acquired evidence to, required if saving to repository, selectable by list, ID, or name.
Use Most Free Volume Whether to automatically select the volume with the most free space for evidence storage when saving locally.
Windows Save Path Local path on Windows systems where evidence will be saved if not using the most free volume.
Linux Save Path Local path on Linux systems where evidence will be saved if not using the most free volume.
macOS Save Path Local path on macOS systems where evidence will be saved if not using the most free volume.
Enable DRONE Whether to enable DRONE analysis with AutoPilot and MITRE ATT&CK detection.
Endpoint Filters (Required) Filters to target specific endpoints for the acquisition task. At least one filter must be defined.

Output

JSON

  • taskId - The ID of the assigned acquisition task.
  • status - The status of the acquisition task assignment.
  • message - Additional message or information about the task assignment.

Dependencies

  • Binalyze AIR API with appropriate credentials

Troubleshooting

  • Ensure that the organization, case, and acquisition profile IDs or names are valid and exist in the Binalyze AIR system.
  • If saving to a repository, verify that the repository ID or name is correct and accessible.
  • At least one endpoint filter must be defined; otherwise, the task assignment will fail.
  • Check network connectivity and API authentication credentials if the task assignment does not proceed.

Discussion