* Glob based
* Time filters
* Yara for Content
![](../../modules/artifacts_and_vql_intro/file-finder-args.png)
---
## Exercise
Find all executables in the user's home directory
---
## Automate file collection+parsing
The goal of VQL is to automate as much of the routine DFIR work as possible
* Example: Collect all browser artifacts
---
## Generic.Collectors.SQLECmd
* Use Generic.Collectors.SQLECmd to automatically locate and parse SQLite files.
* SQLECmd is an open source project to document location of SQLite files
used by various programs (like browsers)
![](../../modules/artifacts_and_vql_intro/sqlite-parsing.png)
## Velociraptor's plugins are robust
Handle file reading errors gracefully
![](../../modules/artifacts_and_vql_intro/sqlite-error-recovery.png)
---
## Inspect the data with the table widget
* Show or hide columns
* Export the modified table to CSV or JSON
![](../../modules/artifacts_and_vql_intro/hide-columns.png)
---
## Inspect the data with the table widget
* Filter or sort using the table widget
![](../../modules/artifacts_and_vql_intro/filtering_tables.png)