Agent Foskett Academy • Defender for Endpoint • Module 3 • Lesson 17

Lesson 17 — Collect Investigation Package

An investigation package gathers diagnostic and forensic information from a device so analysts can examine the endpoint beyond the initial alert and timeline.

The collection is requested from the device response actions in Microsoft Defender for Endpoint, tracked through the Action center and downloaded after the action completes successfully.

This lesson explains when to collect a package, what operational checks to make, how to validate the action and how to protect the downloaded evidence.

Collect early when appropriate. Remediation, reimaging or device changes can remove evidence that may be valuable later.
Agent Foskett Microsoft Defender for Endpoint Collect Investigation Package lesson
What you will learn

This lesson explains how to collect endpoint evidence safely and confirm that the package is available for analysis.

When collection is appropriate
How the collection workflow works
How to track and validate the action
Evidence-handling precautions

Learning objectives

After completing this lesson, you should be able to collect an investigation package as part of a structured endpoint investigation.

  • Explain the purpose of an investigation package.
  • Identify scenarios where collection is useful.
  • Request and track the device action.
  • Validate that collection completed successfully.
  • Protect and document downloaded evidence.

The problem this solves

An alert and device timeline can show that suspicious activity occurred, but deeper analysis may require additional endpoint artefacts.

An investigation package gathers system information from the device and makes it available for further examination without requiring the analyst to collect every item manually.

What is an investigation package?

An investigation package is a downloadable collection of diagnostic and forensic information gathered from a device by Microsoft Defender for Endpoint.

The exact contents can vary by operating system, product capability and configuration. Analysts should treat it as a useful evidence source rather than assume it contains every artefact required for a complete forensic examination.

Suspicious device │ ├── Analyst requests collection ├── Endpoint gathers supported artefacts ├── Package is prepared and uploaded ├── Action status is tracked └── Completed package becomes available for download
Agent Foskett tip:

The package complements the device timeline, Advanced Hunting and Live Response. It does not replace a full forensic acquisition when one is required.

When collection is useful

  • Malware or ransomware is suspected.
  • Persistence is present but not fully understood.
  • PowerShell or command-line activity requires deeper analysis.
  • A device must be escalated to a DFIR team.
  • The endpoint may contain evidence not visible in the alert.
  • Microsoft support or engineering requests diagnostic evidence.

When to collect early

  • Before reimaging or rebuilding the device.
  • Before deleting suspicious files or persistence.
  • Before major remediation changes alter the system state.
  • Before the device is powered down or removed from service.
  • While the endpoint is still online and communicating with Defender.

What the package may contain

Package contents should be treated as platform-dependent and may change as Microsoft updates the service. Depending on the device and supported capabilities, collected information may include categories such as:

Artefact category Why it may help
System and device information Provides operating system, configuration and diagnostic context.
Processes, services and drivers Can reveal suspicious execution, persistence or unusual system components.
Scheduled tasks and startup information Can help identify mechanisms that execute automatically.
Registry and security configuration May expose persistence, policy changes or security-control modifications.
Event and diagnostic information Supports timeline reconstruction and troubleshooting.
Important:

Do not base an investigation on a fixed expected file list. Review the actual downloaded package and current Microsoft guidance for the affected platform.

Device prerequisites

The device must be correctly onboarded, supported and able to communicate with Microsoft Defender for Endpoint.

If the endpoint is offline, unhealthy or unable to receive response actions, the collection may remain pending or fail.

Permissions and authority

Only authorised personnel should collect and download endpoint evidence.

Confirm the analyst has the required portal permissions and that the action is allowed under the organisation's incident response, privacy and evidence-handling procedures.

Before requesting collection

  1. Confirm the device name, user, operating system and incident.
  2. Review the alerts, timeline and existing evidence.
  3. Determine why the package is needed and who will analyse it.
  4. Check whether immediate containment is also required.
  5. Consider device availability, bandwidth and operational impact.
  6. Record the incident or case reference.
  7. Confirm where the downloaded evidence will be stored securely.

Requesting the package

Open the relevant device page in the Microsoft Defender portal and select Collect investigation package from the available response actions.

Add a clear comment explaining why the collection is required, then confirm the action.

Track the action

The collection can be monitored through the device action history and the Microsoft Defender XDR Action center.

Do not assume submission means completion. Confirm the final status and investigate any pending or failed action.

Collection workflow

1. Analyst opens the device page 2. Collect investigation package is selected 3. A reason and case reference are entered 4. The device receives the response action 5. Supported artefacts are gathered 6. The package is prepared and uploaded 7. The Action center records the result 8. The completed package is downloaded 9. Evidence is stored and analysed securely

Pending status

Pending can mean the device has not yet received or completed the instruction.

Check device connectivity, onboarding health and the time the action was submitted before deciding whether to retry or escalate.

Failed status

A failed collection should be investigated rather than silently ignored.

Record the error, verify the device state and consider alternative evidence collection through Live Response or approved local forensic procedures.

How to validate successful collection

  • Confirm the action appears in the Action center or device action history.
  • Verify the status changed to completed or successful.
  • Confirm the package is available for download.
  • Record the request time, completion time and analyst.
  • Download the package to an approved secure location.
  • Confirm the archive opens and contains collected material.
  • Document any missing, corrupted or unexpected results.
Collection requested │ ├── Pending → device has not completed the action ├── Completed → package is available for download ├── Failed → investigate device or service conditions └── Downloaded → evidence handling and analysis begin

Protect the downloaded package

The archive may contain sensitive system, user and security information.

Store it in an approved restricted location, limit access to authorised investigators and apply the organisation's retention and disposal requirements.

Chain of custody

Where legal, regulatory or disciplinary action is possible, evidence handling may require formal chain-of-custody controls.

Record who requested, downloaded, transferred, accessed and analysed the package, and preserve integrity information according to organisational procedures.

Use the package with other evidence

Evidence source Primary value
Device timeline Chronological endpoint events and correlated activity.
Advanced Hunting Organisation-wide searches across devices, identities, email and other telemetry.
Live Response Interactive investigation and approved response commands on the endpoint.
Investigation package Downloadable diagnostic and forensic artefacts for deeper examination.

Example investigation workflow

1. Defender alerts on suspicious PowerShell execution 2. The analyst reviews the device timeline 3. Network activity suggests command-and-control communication 4. The device is isolated to reduce immediate risk 5. An investigation package is requested before major remediation 6. The Action center confirms successful collection 7. The archive is downloaded to secure evidence storage 8. Live Response is used for targeted follow-up checks 9. Advanced Hunting searches for related activity elsewhere 10. Remediation begins after required evidence is preserved
Agent Foskett investigation principle:

Preserve what you may need before changing the endpoint. Once a device is cleaned, rebuilt or wiped, some evidence may be impossible to recover.

Operational considerations

  • The device must be online and responsive.
  • Collection and upload can take time.
  • Package size and bandwidth use can vary.
  • Endpoint performance and user impact should be considered.
  • Critical systems may require coordination with service owners.

What the package does not guarantee

  • It does not contain every possible forensic artefact.
  • It does not automatically determine the root cause.
  • It does not replace memory acquisition or disk imaging.
  • It does not prove the device is clean.
  • It does not remove the need to investigate related devices and accounts.

Common mistakes

Mistake Why it creates risk Better practice
Collecting after the device is wiped Potentially valuable evidence has already been destroyed. Preserve evidence before destructive remediation when circumstances allow.
Assuming the package contains everything Important evidence sources may be overlooked. Use the package alongside timeline, hunting, Live Response and formal forensics.
Ignoring a pending action The package may never have been collected. Track the final status and investigate delays or failures.
Saving evidence in an unsecured location Sensitive endpoint and user information may be exposed or altered. Use approved restricted storage and evidence-handling controls.

Key takeaways

  • An investigation package gathers supported endpoint diagnostic and forensic information.
  • Collect it early when remediation could alter or destroy useful evidence.
  • Track the response action until it completes successfully.
  • Package contents vary and should not be treated as a complete forensic image.
  • Protect the downloaded archive as sensitive evidence.
  • Use it with Advanced Hunting, the device timeline and Live Response.

Related Agent Foskett resources

Continue developing endpoint investigation, evidence collection and containment skills with these connected resources.

Continue learning

Continue through Module 3 — Endpoint Investigations, or return to the wider Defender for Endpoint Academy learning path.

Collect Investigation Package in Microsoft Defender for Endpoint

Microsoft Defender for Endpoint can collect an investigation package containing supported diagnostic and forensic information from a device. Analysts can track the action and download the package after collection completes.

Module 3 Endpoint Investigations — Collect Investigation Package Lesson 17

This Agent Foskett Defender for Endpoint Academy lesson explains when to collect a package, how to request and validate the action, and how to protect downloaded endpoint evidence.