Prepare to attach an evidence file to an investigation. This endpoint does not accept the file. It returns a URL to send the file to and an identifier to pass to the create job endpoint afterwards.
Upload the file with an HTTP PUT to upload_url and send upload_headers exactly as returned by this endpoint. The URL grants access to that one file and stops working at expire_time; a file uploaded before that stays usable afterwards. Prepare one upload per file.
Start the investigation promptly after uploading. There is a limit on how many uploaded files you may hold without using them and starting an investigation from a file releases its slot. A file that no investigation references is discarded once it passes the service's retention window for unused uploads. A file an investigation does reference is kept with that investigation for as long as the investigation itself.
To use this endpoint, your organization must have access to the Adversary Investigation module.
This endpoint does not cost any credits to execute.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
