* Most artifacts have parameters that allow us to be more targeted in
collection
* Being targeted is good because it reduces the amount of data we
collect!
---
## More targeted in collection
* Treat the endpoint as the ultimate source of truth - need more
data? go back and re-fetch it from the endpoint.
data:image/s3,"s3://crabby-images/0faeb/0faeb1df4bf4b737cebdaaf1a4b6f37436c16fee" alt=""
---
## Post processing with notebooks
* Another alternative is to collect all the data and then post-process using the GUI
* Helps us drill into the data and understand what is going on.
data:image/s3,"s3://crabby-images/ef1f2/ef1f28132a2f93f296befe67c06bdfb0a646c812" alt=""
---
# Hunting at scale
---
## Hunting - mass collections
Hunting is Velociraptor's strength - collect the same artifact from thousands of endpoints in minutes!
* Two types of hunts:
* Detection hunts are very targeted aimed at yes/no answer
* Collection hunts collect a lot more data and can be used to
build a baseline.
---
## Exercise - baseline event logs
For this exercise we start a few more clients.
```text
c:\Users\test>cd c:\Users\test\AppData\Local\Temp\
c:\Users\test\AppData\Local\Temp>Velociraptor.exe
--config client.config.yaml pool_client --number 100
```
This starts 100 virtual clients so we can hunt them
* We use pool clients to simulate load on the server
---
## Pool clients
Simply multiple instances of the same client
data:image/s3,"s3://crabby-images/2a135/2a135bd4f769cc8e7724be03f10de6fa91c5c24c" alt=""
---
## Create a hunt
data:image/s3,"s3://crabby-images/b3777/b3777b383cf94c9b7ed931812717782c95597619" alt=""
---
## Select hunt artifacts
data:image/s3,"s3://crabby-images/2a42d/2a42d2df761b51d97c4a71c5aed3fe6583d1d6c6" alt=""
---
## Collect results
data:image/s3,"s3://crabby-images/00f42/00f42696dd777cb6414abffe9a43057ef62839ac" alt=""
---
## Exercise - Stacking
* The previous collection may be considered the baseline
* For this exercise we want to create a few different clients.
* Stop the pool client
* Disable a log channel
* Start the pool client with an additional number of clients
```
Velociraptor.exe --config client.config.yaml pool_client --number 110
```
---
## Stacking can reveal results that stand out
data:image/s3,"s3://crabby-images/807b0/807b0e365496f772023c8e9c9eb37bb7c7f66503" alt=""