Upload an offline triage package

The Forensics Triage feature enables you to create a custom, standalone executable package that collects all of the forensic artifacts in the configuration.

Use the **Upload Offline Triage** to upload archives containing forensic data collected by the offline collector. After the archive has been uploaded, the data is extracted and ingested into the forensics table on the tenant. **Upload Offline Triage** supports uploading packages created on both the Windows and macOS platforms.

### How to upload an offline package in Cortex XSIAM

1. In Cortex XSIAM, select **Investigation & Response** → **Forensics**.
2. Click the link of the relevant investigation.
3. When in the **Collections** page, search for or select the triage and click the menu options button (![menu\_options\_button.png](/docs/images/00c6ea903d780666.png)) to select **Upload Offline Package**.
4. Drag and drop or use the **browse** link to search for the file. More than one offline triage package can be uploaded at a time.

 <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Do not upload memory images captured by the Offline Triage Collector. These images are collected for analysis using third-party tools and are not intended for upload.</p></div>
5. Click **Done**.