Response console

The tabs of the live response panel and what each one needs.

Tabs

TabPurposeNeeds
ShellInteractive terminal on the host.Analyst role, host online.
ProcessesList, kill, suspend, resume.Host online.
FilesBrowse, preview, hash, collect.Host online.
App controlBlock and unblock applications.Host online; enforcement options shown per host.
Collected filesFiles collected from this host, with download.
TriageRun and view triage packages.Host online.

The containment card at the top applies and releases isolation; the sensor card shows the collection state and the required-tools checklist.

Sessions

Everything in the panel reaches the host with your identity attached. Shell sessions use a ticket bound to you and to the host, valid for a minute at open time; the transcript is recorded. Fleet credentials stay on the server.

Offline hosts

Actions on an offline host are queued and execute when it reconnects; the shell opens once the host is online. Queued actions expire after the interval shown in the panel.

See Live response, Network isolation and Application control for the details of each capability.