* Most artifacts have parameters that allow us to be more targeted in
collection
* Being targeted is good because it reduces the amount of data we
collect!
---
## More targeted in collection
* Treat the endpoint as the ultimate source of truth - need more
data? go back and re-fetch it from the endpoint.
data:image/s3,"s3://crabby-images/34a0d/34a0db1a2b5b4b5b3f05c7e7e64ab5706e98e1ad" alt=""
---
## Post processing with notebooks
* Another alternative is to collect all the data and then post-process using the GUI
* Helps us drill into the data and understand what is going on.
data:image/s3,"s3://crabby-images/b0215/b0215e441cc6a24649267f3665107a9e6af95c8d" alt=""
---
# Hunting at scale
---
## Hunting - mass collections
Hunting is Velociraptor's strength - collect the same artifact from thousands of endpoints in minutes!
* Two types of hunts:
* Detection hunts are very targeted aimed at yes/no answer
* Collection hunts collect a lot more data and can be used to
build a baseline.
---
## Exercise - baseline event logs
For this exercise we start a few more clients.
```text
c:\Users\test>cd c:\Users\test\AppData\Local\Temp\
c:\Users\test\AppData\Local\Temp>Velociraptor.exe
--config client.config.yaml pool_client --number 100
```
This starts 100 virtual clients so we can hunt them
* We use pool clients to simulate load on the server
---
## Pool clients
Simply multiple instances of the same client
data:image/s3,"s3://crabby-images/e57c1/e57c193203909d6c0533667b8eeb08dc19675cab" alt=""
---
## Create a hunt
data:image/s3,"s3://crabby-images/94104/941040379418bd6729de7ae7ad95adb83d53447f" alt=""
---
## Select hunt artifacts
data:image/s3,"s3://crabby-images/b3b0e/b3b0e1e1aef33b63bd3bc7953a89be6513ad747c" alt=""
---
## Collect results
data:image/s3,"s3://crabby-images/644b5/644b51c9220f6a831e100981799259d9bc816c04" alt=""
---
## Exercise - Stacking
* The previous collection may be considered the baseline
* For this exercise we want to create a few different clients.
* Stop the pool client
* Disable a log channel
* Start the pool client with an additional number of clients
```
Velociraptor.exe --config client.config.yaml pool_client --number 110
```
---
## Stacking can reveal results that stand out
data:image/s3,"s3://crabby-images/8fd49/8fd49396106e6dd216deccc0d23dd5fc380b5384" alt=""