Searching for events using Evidence of Compromise Search

Search for events using Evidence of Compromise search directly from the endpoints in your environment.
1. On the Investigate page, select the
Endpoint
tab and click
Endpoint Search
.
2. In the Endpoint Search panel, select the
Evidence of Compromise
search type.
3. Enter the search criteria and click
Search
.
See the topic Searching for Events using Endpoint Activity Recorder Search for a list of search values.