These features are new or changed in this release of Endpoint Inspector.
Collection from Telegram
Endpoint Inspector can now collect Telegram cloud data.
Azure Storage Repository
You can now set up an Azure cloud as a storage repository for collections.
Simplified Mobile Collections
When examiners define mobile collections, they no longer need to specify the platform (Android or iOS) of the device. Examiners’ selections in the web interface for Endpoint Inspector automatically collect the appropriate data regardless of the platform of the custodians’ devices.
The web page that custodians see after they provide their authorization token requires them to select the platform of their device. The instructions have also been refined.
Collect from Locked or In-Use Windows Computers
It is now possible to collect files from Windows computers that are in use or locked.
Enhanced YARA Scanning
In addition to files, YARA can now be used to scan memory and processes, on both macOS and Windows computers.
Security
IAfter 15 minutes of inactivity, users are automatically logged out of the web interface for Endpoint Inspector. On the new Security tab on the Settings page, an administrator can set account security policies and define password criteria.
The password criteria appear on the Edit User and Create User panels. This example shows the default password criteria.