Running Aftermath immediately after a threat is detected ensures the collected data fully represents the state of the comprised devices. As a result, Jamf recommends using a Jamf Pro policy and smart groups to automatically run Aftermath when a threat is detected.
Requirements
Computers enrolled with Jamf Pro and Jamf Protect.
Familiarity with Jamf Pro's and Jamf Protect's analytic remediation integration.
For more information, see Setting Up Analytic Remediation With Jamf Pro.
Aftermath is ready to perform a rapid security response based on the policy trigger you created in Jamf Pro. When run, Aftermath writes the collected data in a ZIP file to the /tmp directory; however, you can customize the output location with the --output argument.