Lesson 17 — Collect Investigation Package
An investigation package gathers diagnostic and forensic information from a device so analysts can examine the endpoint beyond the initial alert and timeline.
The collection is requested from the device response actions in Microsoft Defender for Endpoint, tracked through the Action center and downloaded after the action completes successfully.
This lesson explains when to collect a package, what operational checks to make, how to validate the action and how to protect the downloaded evidence.
What you will learn
This lesson explains how to collect endpoint evidence safely and confirm that the package is available for analysis.
Learning objectives
After completing this lesson, you should be able to collect an investigation package as part of a structured endpoint investigation.
- Explain the purpose of an investigation package.
- Identify scenarios where collection is useful.
- Request and track the device action.
- Validate that collection completed successfully.
- Protect and document downloaded evidence.
The problem this solves
An alert and device timeline can show that suspicious activity occurred, but deeper analysis may require additional endpoint artefacts.
An investigation package gathers system information from the device and makes it available for further examination without requiring the analyst to collect every item manually.
What is an investigation package?
An investigation package is a downloadable collection of diagnostic and forensic information gathered from a device by Microsoft Defender for Endpoint.
The exact contents can vary by operating system, product capability and configuration. Analysts should treat it as a useful evidence source rather than assume it contains every artefact required for a complete forensic examination.
The package complements the device timeline, Advanced Hunting and Live Response. It does not replace a full forensic acquisition when one is required.
When collection is useful
- Malware or ransomware is suspected.
- Persistence is present but not fully understood.
- PowerShell or command-line activity requires deeper analysis.
- A device must be escalated to a DFIR team.
- The endpoint may contain evidence not visible in the alert.
- Microsoft support or engineering requests diagnostic evidence.
When to collect early
- Before reimaging or rebuilding the device.
- Before deleting suspicious files or persistence.
- Before major remediation changes alter the system state.
- Before the device is powered down or removed from service.
- While the endpoint is still online and communicating with Defender.
What the package may contain
Package contents should be treated as platform-dependent and may change as Microsoft updates the service. Depending on the device and supported capabilities, collected information may include categories such as:
| Artefact category | Why it may help |
|---|---|
| System and device information | Provides operating system, configuration and diagnostic context. |
| Processes, services and drivers | Can reveal suspicious execution, persistence or unusual system components. |
| Scheduled tasks and startup information | Can help identify mechanisms that execute automatically. |
| Registry and security configuration | May expose persistence, policy changes or security-control modifications. |
| Event and diagnostic information | Supports timeline reconstruction and troubleshooting. |
Do not base an investigation on a fixed expected file list. Review the actual downloaded package and current Microsoft guidance for the affected platform.
Device prerequisites
The device must be correctly onboarded, supported and able to communicate with Microsoft Defender for Endpoint.
If the endpoint is offline, unhealthy or unable to receive response actions, the collection may remain pending or fail.
Permissions and authority
Only authorised personnel should collect and download endpoint evidence.
Confirm the analyst has the required portal permissions and that the action is allowed under the organisation's incident response, privacy and evidence-handling procedures.
Before requesting collection
- Confirm the device name, user, operating system and incident.
- Review the alerts, timeline and existing evidence.
- Determine why the package is needed and who will analyse it.
- Check whether immediate containment is also required.
- Consider device availability, bandwidth and operational impact.
- Record the incident or case reference.
- Confirm where the downloaded evidence will be stored securely.
Requesting the package
Open the relevant device page in the Microsoft Defender portal and select Collect investigation package from the available response actions.
Add a clear comment explaining why the collection is required, then confirm the action.
Track the action
The collection can be monitored through the device action history and the Microsoft Defender XDR Action center.
Do not assume submission means completion. Confirm the final status and investigate any pending or failed action.
Collection workflow
Pending status
Pending can mean the device has not yet received or completed the instruction.
Check device connectivity, onboarding health and the time the action was submitted before deciding whether to retry or escalate.
Failed status
A failed collection should be investigated rather than silently ignored.
Record the error, verify the device state and consider alternative evidence collection through Live Response or approved local forensic procedures.
How to validate successful collection
- Confirm the action appears in the Action center or device action history.
- Verify the status changed to completed or successful.
- Confirm the package is available for download.
- Record the request time, completion time and analyst.
- Download the package to an approved secure location.
- Confirm the archive opens and contains collected material.
- Document any missing, corrupted or unexpected results.
Protect the downloaded package
The archive may contain sensitive system, user and security information.
Store it in an approved restricted location, limit access to authorised investigators and apply the organisation's retention and disposal requirements.
Chain of custody
Where legal, regulatory or disciplinary action is possible, evidence handling may require formal chain-of-custody controls.
Record who requested, downloaded, transferred, accessed and analysed the package, and preserve integrity information according to organisational procedures.
Use the package with other evidence
| Evidence source | Primary value |
|---|---|
| Device timeline | Chronological endpoint events and correlated activity. |
| Advanced Hunting | Organisation-wide searches across devices, identities, email and other telemetry. |
| Live Response | Interactive investigation and approved response commands on the endpoint. |
| Investigation package | Downloadable diagnostic and forensic artefacts for deeper examination. |
Example investigation workflow
Preserve what you may need before changing the endpoint. Once a device is cleaned, rebuilt or wiped, some evidence may be impossible to recover.
Operational considerations
- The device must be online and responsive.
- Collection and upload can take time.
- Package size and bandwidth use can vary.
- Endpoint performance and user impact should be considered.
- Critical systems may require coordination with service owners.
What the package does not guarantee
- It does not contain every possible forensic artefact.
- It does not automatically determine the root cause.
- It does not replace memory acquisition or disk imaging.
- It does not prove the device is clean.
- It does not remove the need to investigate related devices and accounts.
Common mistakes
| Mistake | Why it creates risk | Better practice |
|---|---|---|
| Collecting after the device is wiped | Potentially valuable evidence has already been destroyed. | Preserve evidence before destructive remediation when circumstances allow. |
| Assuming the package contains everything | Important evidence sources may be overlooked. | Use the package alongside timeline, hunting, Live Response and formal forensics. |
| Ignoring a pending action | The package may never have been collected. | Track the final status and investigate delays or failures. |
| Saving evidence in an unsecured location | Sensitive endpoint and user information may be exposed or altered. | Use approved restricted storage and evidence-handling controls. |
Key takeaways
- An investigation package gathers supported endpoint diagnostic and forensic information.
- Collect it early when remediation could alter or destroy useful evidence.
- Track the response action until it completes successfully.
- Package contents vary and should not be treated as a complete forensic image.
- Protect the downloaded archive as sensitive evidence.
- Use it with Advanced Hunting, the device timeline and Live Response.
Related Agent Foskett resources
Continue learning
Collect Investigation Package in Microsoft Defender for Endpoint
Microsoft Defender for Endpoint can collect an investigation package containing supported diagnostic and forensic information from a device. Analysts can track the action and download the package after collection completes.
Module 3 Endpoint Investigations — Collect Investigation Package Lesson 17
This Agent Foskett Defender for Endpoint Academy lesson explains when to collect a package, how to request and validate the action, and how to protect downloaded endpoint evidence.
