# Velociraptor Notebooks ## Post processing
--- ## What are Velociraptor Notbooks? * Interactive evaluation environment * Collaborative * Allows for drilling into data * Central place to document investigation --- ## Creating a notebook data:image/s3,"s3://crabby-images/b3edf/b3edfef88ff3db57ba46d9fff3fd0ecac7aa674a" alt="" --- ## Creating a notebook ### Select the initial template data:image/s3,"s3://crabby-images/779b5/779b5f2e972d0d741696948a3749b932c8fae5e4" alt="" --- ## Creating a notebook data:image/s3,"s3://crabby-images/f1c51/f1c515faecefdb29837fe07185c427a0353f82f7" alt="" --- ## Creating a custom template * Notebooks are built from a template * Templates are just a special kind of artifact * You can get the notebook for this workshop
Here
--- ## Exercise - Add notebook template * Copy the template for this workshop into the artifact editor. * Make sure to save the file and open it in notepad * Sometimes copy/paste does not work because the browser corrupts the text --- ## Exercise - Add notebook template data:image/s3,"s3://crabby-images/7ce21/7ce21d8a4ae0ffe95005b33b9ef3a023527b5952" alt="" --- ## Exercise - Workshop template data:image/s3,"s3://crabby-images/e8abd/e8abd287e4108f53fe9d201da9c3fe6627f80e1e" alt="" --- ## Exercise - Workshop template data:image/s3,"s3://crabby-images/0afdd/0afdd69257446fe1bf0916a88a05254e17dc5376" alt="" --- ## Types of notebook 1. Global Notebooks: Used to collect finished analysis cells * Usually contains information from multiple hunts/collections. 2. Flow Notebooks: Operate on the result of collections 3. Hunt Notebooks: Operate on the result of hunts. --- ## Exercise: Copy cell from collection * Copy a cell from your collection to the global notebook. data:image/s3,"s3://crabby-images/75b5e/75b5ee1adbab805c6c101ebdec1887ff6d988605" alt="" --- ## Exercise: Copy cell from collection data:image/s3,"s3://crabby-images/be388/be3886630ddaed5ab1193ea32dc59bb4b653608c" alt="" --- ## Exercise: Copy cell from collection data:image/s3,"s3://crabby-images/a7976/a7976dee3d8fcd64dbc685f51c1ad78b58223e0b" alt="" --- ## Global notebooks * Use global notebooks as a central place to collate findings * Share the notebook with specific collaborators or publicly (to all users on the server). * When ready, export the notebook for evidentiary storage.