Endpoint API update

We've updated the Sophos Endpoint API to support Forensic Log Collection. Forensic Log Collection is a new feature designed to assist customers during threat investigations. It allows customers to retrieve a variety of forensic artifacts from a device, including Sophos logs, Windows Event Logs, and other relevant operating system data. The tool offers three modes - Standard, Full, and Fast - allowing customers to customize the scope and depth of the data collected.

Collected forensic logs can be uploaded directly to an Amazon S3 bucket. Customers can configure the 'Forensic snapshots' page in Sophos Central with the details of their S3 bucket.

For more details, please refer to the API reference documentation.